CVE-2024-51978: Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51978?
CVE-2024-51978 is considered to have a high severity due to its potential to expose administrative access to unauthenticated attackers.
How do I fix CVE-2024-51978?
To fix CVE-2024-51978, ensure that the default administrator password is changed and never use the default settings for serial number access.
Who is affected by CVE-2024-51978?
CVE-2024-51978 affects users of Brother and Toshiba printers that utilize a default administrator password derived from the serial number.
Can CVE-2024-51978 be exploited remotely?
Yes, CVE-2024-51978 can be exploited remotely if an attacker knows the target device's serial number.
What type of attack is facilitated by CVE-2024-51978?
CVE-2024-51978 can facilitate unauthorized access to the administrative interface of printers, enabling further malicious actions.