{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-35244",
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "state": "PUBLISHED",
        "assignerShortName": "jpcert",
        "dateReserved": "2024-05-22T09:00:11.122Z",
        "datePublished": "2024-11-26T07:38:06.435Z",
        "dateUpdated": "2025-11-04T17:20:50.877Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "vendor": "Sharp Corporation",
                    "product": "Multiple MFPs (multifunction printers)",
                    "versions": [
                        {
                            "version": "See the information provided by Sharp Corporation listed under [References]",
                            "status": "affected"
                        }
                    ]
                },
                {
                    "vendor": "Toshiba Tec Corporation",
                    "product": "Multiple MFPs (multifunction printers)",
                    "versions": [
                        {
                            "version": "See the information provided by Toshiba Tec Corporation listed under [References]",
                            "status": "affected"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "description": "Use of hard-coded credentials",
                            "lang": "en-US",
                            "cweId": "CWE-798",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://global.sharp/products/copier/info/info_security_2024-05.html"
                },
                {
                    "url": "https://jp.sharp/business/print/information/info_security_2024-05.html"
                },
                {
                    "url": "https://www.toshibatec.com/information/20240531_02.html"
                },
                {
                    "url": "https://www.toshibatec.co.jp/information/20240531_02.html"
                },
                {
                    "url": "https://jvn.jp/en/vu/JVNVU93051062/"
                },
                {
                    "url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en-US",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.1,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                    }
                }
            ],
            "providerMetadata": {
                "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
                "shortName": "jpcert",
                "dateUpdated": "2024-11-26T07:38:06.435Z"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 9.1,
                            "attackVector": "NETWORK",
                            "baseSeverity": "CRITICAL",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "NONE",
                            "privilegesRequired": "NONE",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-35244",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-12-04T15:01:16.162778Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-08-27T21:13:00.628Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "http://seclists.org/fulldisclosure/2024/Jul/0"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-04T17:20:50.877Z"
                }
            }
        ]
    }
}