The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/53004 | third party advisory vdb entry |
http://www.securityfocus.com/archive/1/495772/100/0/threaded | broken link mailing list third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44717 | third party advisory vdb entry |
http://www.informit.com/guides/content.aspx?g=security&seqNum=320 | not applicable exploit |
http://www.securityfocus.com/bid/30855 | vdb entry exploit broken link third party advisory |
http://secunia.com/advisories/31631 | vendor advisory broken link third party advisory |