An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.
History

Thu, 26 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec. Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
References

Wed, 25 Jun 2025 07:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.
Title Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec.
Weaknesses CWE-538
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2025-06-25T07:15:16.800Z

Updated: 2025-06-26T14:34:12.258Z

Reserved: 2024-11-04T17:19:18.808Z

Link: CVE-2024-51977

cve-icon Vulnrichment

Updated: 2025-06-26T14:34:00.948Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-25T08:15:30.053

Modified: 2025-06-26T18:58:14.280

Link: CVE-2024-51977

cve-icon Redhat

No data.