CVE Intelligence
Skip to main content
HIGH

CVE-2024-51982

CVE-2024-51982 — Unauthenticated Denial of Service (DoS) via malformed PJL request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and Rico

An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device. A malformed PJL variable FORMLINES is set to a non number value causing the target to crash.

Published Updated Sources: cvelistV5, rapid7

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

9%

chance of exploitation in 30 days

Affects

brother industries

218 products listed

CVSS base

7.5

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

PoC

none · proof-of-concept · active

Automatable

Yes

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Products (218)

hl l8260cdnhl l8260cdwhl l8360cdwhl l8360cdwthl l9310cdwdcp l8410cdwmfc l8610cdwmfc l8690cdwmfc l8900cdwmfc l9570cdwmfc l9577cdwhl l2325dwhl l2350dwhl l2351dwhl l2352dwhl l2357dwhl l2370dnhl l2371dnhl l2372dnhl 2590dnhl l2370dwhl l2370dwxlhl l2375dwhl l2376dwhl b2050dnhl b2080dwhl l2385dwhl l2386dwhl 2595dwhl l2350dwrhl l2370dnrhl l2375dwrhl l2395dwmfc l2730dwmfc l2732dwmfc l2750dwmfc l2750dwxlmfc l2751dwmfc l2770dwmfc l2771dwmfc l2730dwrmfc l2750dwrdcp 7195dwmfc 7895dwmfc l2730dnhl l2390dwdcp l2530dwdcp l2531dwdcp l2532dwdcp l2535dwdcp l2537dwdcp b7520dwdcp l2550dndcp l2550dwdcp l2551dndcp l2551dwdcp l2552dndcp b7535dwmfc l2690dwmfc l2710dnmfc l2712dnmfc l2710dwmfc l2712dwmfc l2713dwmfc l2715dwmfc l2716dwmfc l2717dwmfc b7715dwdcp l2530dwrdcp l2550dnrmfc l2710dnrmfc l2710dwrfax l2710dndcp 7190dndcp b7530dnmfc 7890dnmfc b7720dndcp 7090dwdcp 7190dwhl l3210cwhl l3230cdnhl l3230cdwhl 3160cdwhl l3270cdwhl 3190cdwdcp l3510cdwdcp l3517cdwhl l3290cdwdcp l3551cdwdcp l3550cdwdcp 9030cdnmfc l3710cdwmfc l3730cdnmfc 9150cdnmfc l3735cdnmfc l3745cdwmfc l3750cdwmfc 9350cdwmfc l3770cdwdcp t520wdcp t525wdcp t720dwdcp t725dwdcp t820dwdcp t825dwmfc t920dwmfc t925dwdcp t220dcp t225dcp t226dcp t420wdcp t425wdcp t426wdcp t428wdcp c421wmfc j805dwdcp j1100dwmfc j995dwmfc j1300dwdcp j988nmfc j1500nmfc j1605dnmfc j5845dw xlmfc j5945dwmfc j6945dwmfc j6947dwhl j6000dwhl j6100dwmfc j6997cdwmfc j6999cdwhl j6000cdwmfc t4500dwhl t4000dwmfc j5330dwmfc j5335dwmfc j2330dwmfc j5730dwmfc j5830dwmfc j5930dwmfc j2730dwmfc j6530dwmfc j6730dwmfc j3530dwmfc j6930dwmfc j6935dwmfc j3930dwmfc j6535dwmfc j6580cdwmfc j6980cdwmfc j6995cdwmfc j5630cdwmfc j6583cdwmfc j6983cdwdcp t510wdcp t710wmfc t810wmfc t910dwdcp j572dwmfc j491dwmfc j497dwdcp j772dwdcp j774dwmfc j890dwmfc j895dwmfc j690dwdcp j572ndcp j577ndcp j582ndcp j972ndcp j973n w bdcp j978n w bdcp j981ndcp j982n w bmfc j893nmfc j898nmfc j738dnmfc j738dwnmfc j998dnmfc j998dwndcp j587ndocuprint p235 ddocuprint p275 dwdocuprint p285 dwdocuprint p288 dwdocuprint m235 dwdocuprint m235 zdocuprint m275 zdocuprint m285 zdocuprint m288 dwdocuprint m288 zsp 230dnwp 201wm 340wsp 230sfnwm 340fwdcp j987n w bdcp t510w chinadcp t710w chinamfc j805dwxlmfc j815dwxlmfc j995dwxlmfc t810w chinadcp b7520dw chinadcp b7535dw chinadcp l2535dw chinadcp l2550dw chinadcp l2550dw japandcp l2550dw taiwanmfc l2715dw taiwan korea hong kongmfc l2750dw japanmfc l3770cdw japanmfc l8610cdw japanmfc l9570cdw japanads 2400nads 2800wads 3000nads 3600wmfc j903n

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
7.5CVSS 3.1HIGHcvelistV5

Weakness & attack patterns

  • CWE-1286

References

6 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.