An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing password is present for an external service, the attacker can force the target device to authenticate to an attacker controlled device using the existing credentials for that external service. In the case of an external LDAP or FTP service, this will disclose the plaintext password for that external service to the attacker.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Authenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec. | Authenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. |
References |
|
Wed, 25 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Jun 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing password is present for an external service, the attacker can force the target device to authenticate to an attacker controlled device using the existing credentials for that external service. In the case of an external LDAP or FTP service, this will disclose the plaintext password for that external service to the attacker. | |
Title | Authenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, RICOH, and Toshiba Tec. | |
Weaknesses | CWE-522 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: rapid7
Published: 2025-06-25T07:28:17.332Z
Updated: 2025-06-25T14:17:15.174Z
Reserved: 2024-11-04T17:19:18.809Z
Link: CVE-2024-51984

Updated: 2025-06-25T12:24:24.812Z

Status : Awaiting Analysis
Published: 2025-06-25T08:15:33.220
Modified: 2025-06-26T18:58:14.280
Link: CVE-2024-51984

No data.