CVE-2024-27974: CSRF
Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor listed under [References].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27974?
CVE-2024-27974 is classified as a high-severity cross-site request forgery vulnerability affecting FUJIFILM printers.
How does CVE-2024-27974 affect users?
CVE-2024-27974 allows an unauthenticated attacker to alter user information, including sensitive credentials if the user is an administrator.
What devices are impacted by CVE-2024-27974?
CVE-2024-27974 affects FUJIFILM printers using CentreWare Internet Services and Internet Services.
How can I mitigate CVE-2024-27974?
Mitigation for CVE-2024-27974 includes updating firmware and applying available security patches from FUJIFILM.
Is it safe to use FUJIFILM printers affected by CVE-2024-27974?
Using FUJIFILM printers affected by CVE-2024-27974 poses a security risk until the vulnerability is addressed.