CVE-2024-51977 is an information disclosure vulnerability affecting numerous Brother printer models, allowing an unauthenticated attacker to retrieve sensitive device information. An attacker can exploit this by making a GET request to a specific URI path on the device's HTTP, HTTPS, or IPP services, bypassing authentication. The vulnerability has a CVSS score of 5.3 (Medium), indicating low attack complexity and no user interaction, but only a low impact on confidentiality. While not listed in CISA's KEV catalog, exploit intelligence shows available Metasploit modules and Nuclei templates, and it has garnered significant community discussion and media coverage, suggesting a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Brother Industries, Ltd | DCP-1610W | >= 0, <= ZBCNA affecteddefault unaffected | |
| Brother Industries, Ltd | DCP-1610WE | >= 0, <= ZBCNA affecteddefault unaffected | |
| Brother Industries, Ltd | DCP-1610WR | >= 0, <= ZBCNA affecteddefault unaffected | |
| Brother Industries, Ltd | DCP-1612W | >= 0, <= ZBCNA affecteddefault unaffected | |
| Brother Industries, Ltd | DCP-1612WE | >= 0, <= ZBCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.