@UKTechHub
.
.

Critical Alert for Brother Device Owners Security researchers at Rapid7 have uncovered eight serious vulnerabilities affecting 689 Brother models, including printers, scanners, and label makers. These flaws also impact select devices from Fujifilm, Ricoh, Toshiba, and…

UKTH forums 💻 Computers Printers & Scanners Critical Alert for Brother Device Owners Security researchers at Rapid7 have uncovered eight serious vulnerabilities affecting 689 Brother models, including printers, scanners, and label makers. These flaws also impact select devices from Fujifilm, Ricoh, Toshiba, and...

Viewing 1 post (of 1 total)
  • Author
    Posts
  • #38150
    UK SentinelUK Sentinel
    Keymaster
    • Replies 8,507
    • The Skipper

    Security researchers at Rapid7 have uncovered eight serious vulnerabilities affecting 689 Brother models, including printers, scanners, and label makers. These flaws also impact select devices from Fujifilm, Ricoh, Toshiba, and Konica Minolta, bringing the total to 748 affected models.

    Key Vulnerability: CVE-2024-51978

    • Severity: 9.8 (Critical)
    • Issue: Attackers can derive the default admin password using the device’s serial number.
    • Impact: Remote takeover of the device and potential access to connected systems.
    • Fix: Cannot be fully patched via firmware—requires a manufacturing process change.

    Other Vulnerabilities Include:

    CVE IDDescriptionCVSS ScoreAccess Level
    CVE-2024-51977Leak of sensitive information via HTTP/IPP5.3Unauthenticated
    CVE-2024-51979Stack-based buffer overflow7.2Authenticated
    CVE-2024-51980Forced TCP connection5.3Unauthenticated
    CVE-2024-51981Arbitrary HTTP request execution5.3Unauthenticated
    CVE-2024-51982/83Device crash via PJL or HTTP7.5Unauthenticated
    CVE-2024-51984Disclosure of external service passwords (e.g., LDAP, FTP)6.8Authenticated

    What You Can Do

    • Change the default admin password immediately.
    • Check if your model is affected using.
    • Apply firmware updates where available—seven of the eight vulnerabilities have patches.
    • For CVE-2024-51978, only newly manufactured devices will be fully protected.

    https://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixed/

    In a completely sane world, madness is the only freedom (J.G.Ballard).

Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.
Latest Posts