CVE-2024-51982: Unauthenticated Denial of Service (DoS) via malformed PJL request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and Ricoh.
An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device. A malformed PJL variable FORMLINES is set to a non number value causing the target to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51982?
CVE-2024-51982 is considered a high severity vulnerability due to its potential to crash devices repeatedly.
How do I fix CVE-2024-51982?
To fix CVE-2024-51982, ensure that your printer models are updated with the latest firmware provided by the manufacturer.
Who is affected by CVE-2024-51982?
CVE-2024-51982 affects multiple printer models from Brother, FUJIFILM, and Ricoh.
What type of attack does CVE-2024-51982 involve?
CVE-2024-51982 involves an unauthenticated attacker exploiting TCP port 9100 to issue PJL commands that crash the printer device.
Can CVE-2024-51982 be exploited remotely?
Yes, CVE-2024-51982 can be exploited remotely if an attacker has network access to the affected printer model.