CVE-2024-21824
Estado: AplazadaMedia (5.3)—
Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-306
Referencias
- https://jvn.jp/en/jp/JVN82749078/
- https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000
- https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html
- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002
- https://www.toshibatec.com/information/20240306_01.html
- https://jvn.jp/en/jp/JVN82749078/
- https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000
- https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html
- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002
- https://www.toshibatec.com/information/20240306_01.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-21824",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-21824",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-17T18:20:15.364083Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "BROTHER INDUSTRIES, LTD.",
"product": "Multiple printers and scanners",
"versions": [
{
"status": "affected",
"version": "see the information provided by the vendor"
}
]
},
{
"vendor": "FUJIFILM Business Innovation Corp.",
"product": "Multiple printers and scanners",
"versions": [
{
"status": "affected",
"version": "see the information provided by the vendor"
}
]
},
{
"vendor": "Toshiba Tec Corporation",
"product": "Multiple printers and scanners",
"versions": [
{
"status": "affected",
"version": "see the information provided by the vendor"
}
]
},
{
"vendor": "RICOH COMPANY, LTD.",
"product": "Multiple printers and scanners",
"versions": [
{
"status": "affected",
"version": "see the information provided by the vendor"
}
]
}
]
}
],
"published": "2024-03-18T08:15:06.087",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN82749078/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.toshibatec.com/information/20240306_01.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN82749078/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faqp00100601_000",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faq00100823_000",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.fujifilm.com/fbglobal/eng/company/news/notice/2024/0306_2_announce.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2024-000002",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.toshibatec.com/information/20240306_01.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de autenticación incorrecta en varias impresoras y escáneres que implementan la administración basada en web proporcionada por BROTHER INDUSTRIES, LTD. Si se explota esta vulnerabilidad, un usuario adyacente a la red que pueda acceder al producto puede hacerse pasar por un usuario administrativo. En cuanto a los detalles de los nombres de productos, números de modelo y versiones afectados, consulte la información proporcionada por los respectivos proveedores que figuran en [Referencias]."
}
],
"lastModified": "2026-06-17T07:10:13.700",
"sourceIdentifier": "vultures@jpcert.or.jp"
}