CVE Vulnerabilities

CVE-2017-2161

Direct Request ('Forced Browsing')

Published: May 22, 2017 | Modified: Apr 20, 2025
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.7 LOW
AV:A/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

FlashAirTM SDHC Memory Card (SD-WE Series ) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series ) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
FlashairToshiba*2.00.04 (including)
FlashairToshiba*3.00.02 (including)

Potential Mitigations

References