[Japanese] | |
JVNDB-2024-000027 | |
FUJIFILM Business Innovation Corp. printers vulnerable to cross-site request forgery | |
Overview | |
Multiple printers provided by FUJIFILM Business Innovation Corp. contain a cross-site request forgery vulnerability (CWE-352). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 6.5 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 2.6 (Low) [IPA Score]
| |
Affected Products | |
As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor listed below. | |
FUJIFILM Business Innovation Corp. (former Fuji Xerox Co., Ltd.) | |
| |
Impact | |
If a user views a malicious page while logging in, the user information may be altered. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. | |
Solution | |
[Apply workarounds] | |
Vendor Information | |
FUJIFILM Business Innovation Corp. (former Fuji Xerox Co., Ltd.) | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/03/06 |
Date First Published | 2024/03/06 |
Date Last Updated | 2024/03/06 |