常見問題&故障排除

常見問題&故障排除

Web Based Management Vulnerabilities on Brother Machines: CVE-2024-21824 and CVE-2024-22475

Description

 

Session Management Vulnerability

Vulnerability Reference: CVE-2024-21824

Attackers can gain access to the server's setting screen by obtaining session IDs of logged-in users and impersonating them, or by stealing login credentials and tricking users into opening malicious URLs.

Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21824

 

Cross-Site Request Forgery (CSRF) Vulnerability
Vulnerability Reference: CVE-2024-22475
If authenticated users unknowingly submit requests to their machines via a malicious site set up for CSRF attacks, it may allow the attackers to change the Web Based Management settings.
Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22475

 

 

Possible Solutions

  1. Click here to see the affected models and their firmware update status.
  2. Update the machine’s firmware using the Firmware Update Tool available in your printer model’s Downloads section.

如果您需要進一步的協助, 請聯絡Brother客戶服務:

內容意見回饋

請於下方回饋您的意見以幫助我們提升服務的品質

步驟一: 此頁面的資訊對您有幫助嗎

步驟二: 你有任何其他想要提出的意見嗎?

請注意, 此表格僅用做意見回饋使用