CVE-2024-12511
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Exploitability: 2.8 / Impact: 4.7
Source: 10b61619-3869-496c-8a1e-f291b0e71e3f (Secondary)
Description
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
Related CWEs
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-522
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References (1)
Source: 10b61619-3869-496c-8a1e-f291b0e71e3f
Timeline
No history available yet.