First published: Sat Apr 19 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Toshibatec E-studio-232 | ||
Toshibatec E-studio-233 | ||
Toshibatec E-studio-282 | ||
Toshibatec E-studio-283 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1990 is classified as a high severity vulnerability due to its capability to allow unauthorized changes to administrator passwords.
To fix CVE-2014-1990, ensure your TOSHIBA TEC e-Studio devices are updated to the latest firmware version that addresses the CSRF vulnerability.
CVE-2014-1990 affects users of TOSHIBA TEC e-Studio models 232, 233, 282, and 283 that utilize the TopAccess management utility.
CVE-2014-1990 enables a cross-site request forgery (CSRF) attack that can hijack authentication of admin users.
Yes, CVE-2014-1990 remains a concern for users who have not yet implemented security updates to mitigate the vulnerability.