First published: Thu Dec 31 2015(Updated: )
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted request to TCP port 54138.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Toshiba 4690 Point Of Sale Operating System | =6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4876 is considered a medium severity vulnerability due to its exploitation potential targeting sensitive system environment variables.
To fix CVE-2014-4876, restrict access to the ADXSITCF logical name to prevent unauthorized remote requests.
CVE-2014-4876 affects Toshiba 4690 Operating System version 6.3.
CVE-2014-4876 allows remote attackers to read potentially sensitive system environment variables.
There is no specific patch listed for CVE-2014-4876, so implementing access restrictions is recommended.