6.8
CVSSv2

CVE-2014-1990

Published: 19/04/2014 Updated: 21/04/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote malicious users to hijack the authentication of administrators for requests that change passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

toshibatec e-studio-282 -

toshibatec e-studio-232 -

toshibatec e-studio-233 -

toshibatec e-studio-283 -

Exploits

# Exploit Title: TOSHIBA e-Studio 232/233/282/283 Change Admin Password CSRF Vulnerability # Date: 02102013 # Exploit Author: Hubert Gradek (PL) # Affected version: firmware T377SY0EXXX # Tested on: TOSHIBA e-Studio 232 (T377SY0E354) / 233 (T377SY0E331) # CVE : No CVE exists - 0day exploit Password must be minimum 6 digits!!! login: Admin EX ...