CVE-2014-4876: Infoleak
Published Dec 31, 2015
·Updated
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
Affected Software
1 affected component
Toshiba 4690 Operating System=6.3
Event History
Dec 31, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4876?
CVE-2014-4876 is considered a medium severity vulnerability due to its exploitation potential targeting sensitive system environment variables.
2
How do I fix CVE-2014-4876?
To fix CVE-2014-4876, restrict access to the ADXSITCF logical name to prevent unauthorized remote requests.
3
Which systems are affected by CVE-2014-4876?
CVE-2014-4876 affects Toshiba 4690 Operating System version 6.3.
4
What type of attack does CVE-2014-4876 allow?
CVE-2014-4876 allows remote attackers to read potentially sensitive system environment variables.
5
Is there a patch available for CVE-2014-4876?
There is no specific patch listed for CVE-2014-4876, so implementing access restrictions is recommended.