peter bassill · operator
$ cve CVE-2024-51978 JSON

CVE-2024-51978

9.8
CRITICAL · CVSS 3.1 · EPSS 15.7% (pctl 97)

Patch early

EPSS 15.7% — above the 10% action threshold.

Description

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.71% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-1391
On CISA KEVno
Public exploitnone known
Published2025-06-25
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD