Описание
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Ссылки
EPSS
Процентиль: 98%
0.23635
Средний
9.8 Critical
CVSS3
Дефекты
CWE-1391
Связанные уязвимости
CVSS3: 9.8
github
около 1 года назад
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
EPSS
Процентиль: 98%
0.23635
Средний
9.8 Critical
CVSS3
Дефекты
CWE-1391