CVE-2024-51978
Last modified
CVE-2024-51978 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.. EPSS estimates a 23.64% chance of exploitation in the next 30 days.
Description
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-51978?
How severe is CVE-2024-51978?
How do I fix CVE-2024-51978?
Are you affected by CVE-2024-51978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
