CVE-2024-51983

An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device.
Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) Un atacante no autenticado que pueda conectarse a la función de Servicios Web (puerto HTTP TCP 80) puede emitir una solicitud SOAP WS-Scan con un valor JobToken inesperado que bloqueará el dispositivo objetivo. El dispositivo se reiniciará, tras lo cual el atacante puede volver a ejecutar el comando para bloquearlo repetidamente.

25 Jun 2025, 15:15

Type Values Removed Values Added
References
  • () https://www.fujifilm.com/fbglobal/eng/company/news/notice/2025/0625_announce.html -
  • () https://www.konicaminolta.com/global-en/security/advisory/pdf/km-2025-0001.pdf -
  • () https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000007 -
  • () https://www.toshibatec.com/information/20250625_02.html -

25 Jun 2025, 13:15

Type Values Removed Values Added
References () https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf - () https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf -

25 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 08:15

Updated : 2025-06-26 18:58


NVD link : CVE-2024-51983

Mitre link : CVE-2024-51983

CVE.ORG link : CVE-2024-51983


JSON object : View

Products Affected

No product.

CWE
CWE-1286

Improper Validation of Syntactic Correctness of Input