Overview
The Toshiba 4690 operating system, version 6 (Release 3) and possibly earlier versions, contains an information disclosure vulnerability.
Description
CWE-200: Information Exposure - CVE-2014-4876 The Toshiba 4690 operating system, version 6 (Release 3) and possibly earlier versions, contains an information disclosure vulnerability. Sending a special string to TCP port 54138 causes system environment variables and other information to be returned to an unauthenticated client. The vendor has stated that this disclosure occurs by design as part of the support capabilities of 4690 and that: |
Impact
A remote, unauthenticated attacker is able to view potentially sensitive system information. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem and recommends the following workaround. |
Disable services |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Temporal | 4.5 | E:F/RL:W/RC:C |
Environmental | 3.4 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to David Odell for reporting this vulnerability.
This document was written by Todd Lewellen and Joel Land.
Other Information
CVE IDs: | CVE-2014-4876 |
Date Public: | 2015-06-08 |
Date First Published: | 2015-06-08 |
Date Last Updated: | 2015-06-08 13:54 UTC |
Document Revision: | 18 |