PT-2024-26933 · Sharp+1 · Multiple Mfps+18
Jarrod Stebick
·
Published
2024-11-26
·
Updated
2024-12-01
·
CVE-2024-36251
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Affected devices (affected versions not specified)
Description
The web interface of the affected devices processes some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to
billcodedef sub sel.html is not processed properly, causing the device to crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multiple Mfps
Bp-B537Wr
Bp-B540Wr
Bp-B547Wd
Bp-B550Wd
Mx-B355W
Mx-B455W
Mx-M2630
Mx-M3050
Mx-M3070
Mx-M3550
Mx-M3570
Mx-M4050
Mx-M4070
Mx-M5050
Mx-M5070
Mx-M6050
Mx-M6070
Mx-M905