CVE-2024-51984

An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing password is present for an external service, the attacker can force the target device to authenticate to an attacker controlled device using the existing credentials for that external service. In the case of an external LDAP or FTP service, this will disclose the plaintext password for that external service to the attacker.
Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) Un atacante autenticado puede reconfigurar el dispositivo objetivo para que use un servicio externo (como LDAP o FTP) controlado por él. Si existe una contraseña para un servicio externo, el atacante puede forzar al dispositivo objetivo a autenticarse en un dispositivo controlado por él utilizando las credenciales existentes para ese servicio externo. En el caso de un servicio LDAP o FTP externo, esto revelará la contraseña en texto plano de ese servicio externo al atacante.

25 Jun 2025, 15:15

Type Values Removed Values Added
References
  • () https://www.fujifilm.com/fbglobal/eng/company/news/notice/2025/0625_announce.html -
  • () https://www.konicaminolta.com/global-en/security/advisory/pdf/km-2025-0001.pdf -
  • () https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000007 -
  • () https://www.toshibatec.com/information/20250625_02.html -

25 Jun 2025, 13:15

Type Values Removed Values Added
References () https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf - () https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf -

25 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 08:15

Updated : 2025-06-26 18:58


NVD link : CVE-2024-51984

Mitre link : CVE-2024-51984

CVE.ORG link : CVE-2024-51984


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials