← Volver a CVEs
CVE-2024-51977
MEDIUM5.3
Descripcion
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.
Detalles CVE
Puntuacion CVSS v3.15.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado6/25/2025
Ultima modificacion7/25/2025
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-538
Referencias
https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-51977.yaml(cve@rapid7.com)
https://github.com/sfewer-r7/BrotherVulnerabilities(cve@rapid7.com)
https://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixed(cve@rapid7.com)
https://www.toshibatec.com/information/20250625_02.html(cve@rapid7.com)
https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.