← All CVEs

CVE-2024-51978

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

9.8
CVSS
15.5%
EPSS (exploit prob.)
97th
EPSS percentile
2025-06-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-1391

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-51978