CVE Vulnerabilities

CVE-2017-2161

Direct Request ('Forced Browsing')

Published: May 22, 2017 | Modified: Oct 03, 2019
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.7 LOW
AV:A/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

FlashAirTM SDHC Memory Card (SD-WE Series ) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series ) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Flashair Toshiba * 2.00.04 (including)
Flashair Toshiba * 3.00.02 (including)

Potential Mitigations

References