CVE-2017-2149 Information
Description
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE seriesW-03) V3.00.01 SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC seriesW-02) V2.00.03 and earlier SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://jvn.jp/en/jp/JVN05340816/index.html http://www.securityfocus.com/bid/97697 http://www.toshiba-personalstorage.net/news/20170414.htm
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: