CVE-2024-27974 - CVE House
Back to Database
Status published Unknown CVE-2024-27974

Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare...

Vulnerability Description

Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor listed under [References].

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-27974

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

FUJIFILM Business Inovation Corp.

View all reports →

Affected Software

DocuPrint P450 d, DocuPrint P450 JM, DocuPrint P450 ps, DocuPrint P455 d, DocuPrint M455 df, DocuPrint C2255, DocuPrint C2450, DocuPrint C2450 II, DocuPrint C3200A, DocuPrint C3350, DocuPrint C3360, DocuPrint C3450 d, DocuPrint C3450 d II, DocuPrint 4050, DocuPrint 4060, DocuPrint 5060, DocuCentre-IV C2260, DocuCentre-IV C2270, DocuCentre-IV C3370, DocuCentre-IV C4470, DocuCentre-IV C5570, ApeosPort-IV C2270, ApeosPort-IV C3370, ApeosPort-IV C4470, ApeosPort-IV C5570, ApeosPort-IV C2270 R, ApeosPort-IV C3370 R, ApeosPort-IV C4470 R, ApeosPort-IV C5570 R, ApeosWide 6050/3030, DocuWide 6057/3037, DocuWide 6055, DocuWide 3035, DocuWide C842, DocuWide 2055, DocuWide 9098α, DocuWide 9095α
Vulnerable Versions:
all versions

Timeline

Official Publish: March 18th, 2024
Last Modified: October 31st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.