CVE-2024-51979 Details
Description
An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.
A stack-based buffer overflow vulnerability has been identified in certain Brother multifunction printers, scanners, and label makers. This vulnerability allows an authenticated attacker to overwrite the return address of a function, potentially leading to arbitrary code execution. The issue arises when the device's HTTP, HTTPS, or IPP services receive a malformed request with an empty Origin header and a Referer header containing a host value longer than 64 bytes. The vulnerability is present in 689 models across Brother's range of devices, as well as 46 models from FUJIFILM Business Innovation, 5 models from Ricoh, and 2 models from Toshiba Tec Corporation.
Brother has released firmware updates for this vulnerability. Users should check the Brother website for the latest firmware version, install the update, and change the default administrator password via the Web Based Management interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2025CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Brother MFC-L9570CDW | All versions |
CPE
Remediation
| |
| Brother DCP-L2530DW | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | CVE Modified | [email protected] |
| Jun 25, 2025 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | New CVE Received | [email protected] |
Volerion