First published: Mon May 22 2017(Updated: )
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Toshiba FlashAir | <=2.00.04 | |
Toshiba FlashAir | <=3.00.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2161 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive image data.
CVE-2017-2161 affects the Toshiba FlashAir SDHC Memory Card models with firmware versions V3.00.02 and earlier, and V2.00.04 and earlier.
To fix CVE-2017-2161, update the firmware of affected Toshiba FlashAir SDHC Memory Cards to the latest version available from the manufacturer.
CVE-2017-2161 allows authenticated attackers to bypass access restrictions and retrieve unauthorized image data from the affected devices.
CVE-2017-2161 poses significant risks to user privacy as it enables unauthorized access to potentially sensitive personal images stored on the affected memory cards.