An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HTTP request smuggling. This SSRF leverages the WS-Addressing feature used during a WS-Eventing subscription SOAP operation. The attacker can control all the HTTP data sent in the SSRF connection, but the attacker can not receive any data back from this connection.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Unauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec. | Unauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc. |
References |
|
Wed, 25 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Jun 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HTTP request smuggling. This SSRF leverages the WS-Addressing feature used during a WS-Eventing subscription SOAP operation. The attacker can control all the HTTP data sent in the SSRF connection, but the attacker can not receive any data back from this connection. | |
Title | Unauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec. | |
Weaknesses | CWE-918 CWE-93 |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: rapid7
Published: 2025-06-25T07:23:15.189Z
Updated: 2025-06-25T14:12:11.314Z
Reserved: 2024-11-04T17:19:18.809Z
Link: CVE-2024-51981

Updated: 2025-06-25T12:28:32.942Z

Status : Awaiting Analysis
Published: 2025-06-25T08:15:32.293
Modified: 2025-06-26T18:58:14.280
Link: CVE-2024-51981

No data.