9.3
CVSSv2

CVE-2017-2149

Published: 28/04/2017 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and previous versions, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and previous versions, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and previous versions, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and previous versions, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and previous versions, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and previous versions allows remote malicious users to gain privileges via a Trojan horse DLL in an unspecified directory.

Vulnerable Product Search on Vulmon Subscribe to Product

toshiba flashair