CVE-2024-21824

medium

Description

Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

References

https://www.toshibatec.com/information/20240306_01.html

https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002

https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html

https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000

https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000

https://jvn.jp/en/jp/JVN82749078/

Details

Source: Mitre, NVD

Published: 2024-03-18

Updated: 2024-11-07

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium