CVE-2024-22475

medium

Description

Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to perform unintended operations on the affected product. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

References

https://www.toshibatec.com/information/20240306_01.html

https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002

https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html

https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000

https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000

https://jvn.jp/en/jp/JVN82749078/

Details

Source: Mitre, NVD

Published: 2024-03-18

Updated: 2024-10-27

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L

Severity: Medium