CVE-2024-22475
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
18/03/2024
Last modified:
27/10/2024
Description
Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to perform unintended operations on the affected product. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://jvn.jp/en/jp/JVN82749078/
- https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000
- https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html
- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002
- https://www.toshibatec.com/information/20240306_01.html



