CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-51978

CVSS 9.8v3.1pub. 2025-06-25upd. 2026-04-15

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

🤖 AI Analysis
How it works

An attacker who knows the serial number of the target device is able to algorithmically calculate the default administrator password (CWE-1391 — use of weak credential generation algorithm). The device serial number can be obtained remotely by an unauthenticated attacker using the associated vulnerability CVE-2024-51977 via HTTP, HTTPS, or IPP protocols, as well as through PJL or SNMP requests. The combination of both vulnerabilities creates a fully remote attack chain requiring no privileges.

Impact

An attacker gains full administrative access to the device, which may lead to taking control, disclosure of processed documents, modification of network configuration, or using the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references (Brother support page: https://support.brother.com). Additionally, it is recommended to immediately change the default administrator passwords on all devices and restrict access to HTTP, HTTPS, IPP, PJL, and SNMP protocols only to trusted network segments.

Who is affected

Brother devices — a detailed list of affected models is indicated in the manufacturer's references (Brother support page and published whitepaper).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References