CVE-2024-51978
CRITICALDescription
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Is your site exposed to CVE-2024-51978?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-51978? +
How severe is CVE-2024-51978? +
How do I check if I'm vulnerable to CVE-2024-51978? +
Related Vulnerabilities
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 …
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the …
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a …