An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
References
Configurations
No configuration.
History
27 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Jun 2025, 18:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Jun 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Jun 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf - |
25 Jun 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-25 08:15
Updated : 2025-06-27 14:15
NVD link : CVE-2024-51978
Mitre link : CVE-2024-51978
CVE.ORG link : CVE-2024-51978
JSON object : View
Products Affected
No product.
CWE
CWE-1391
Use of Weak Credentials