CVE-2024-51983
Unauthenticated Denial of Service (DoS) via malformed WS-Scan request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
Description
An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device.
In plain language
AI Worth attentionIf you use one of the listed Brother printer models, someone who can reach its web service can repeatedly take it offline; typical small businesses should restrict access and ask their vendor for a fix.
Unauthenticated network DoS in the WS-Scan SOAP service: an unexpected JobToken in a malformed request crashes and reboots the device, enabling repeated service disruption.
What to do now
- Check whether you use hl-l8260cdn, hl-l8260cdw, hl-l8360cdw, hl-l8360cdwt, hl-l9310cdw, dcp-l8410cdw, mfc-l8610cdw, mfc-l8690cdw, mfc-l8900cdw, or mfc-l9570cdw.
- Restrict access to the printer’s web service on port 80 so only trusted internal systems can reach it; do not expose it to the internet.
- Ask Brother or your printer support provider for a security update for CVE-2024-51983; no fixed version has been published in the available information.
- Watch for unexplained printer reboots or repeated loss of printing and scanning service.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-51983 and every CVE in our database. Create a free account — no credit card required.
Create Free Account