CVE-2024-12782

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 19, 2024
Updated: Dec 27, 2024
CWE ID 285
CWE ID 266

Summary

CVE-2024-12782 is a newly disclosed critical vulnerability affecting the Fujifilm Apeos C3070, C5570, and C6580 models with software versions up to 24.8.28. This issue lies within the Web Interface component and involves unknown code in the /home/index.html#hashHome file. The vulnerability grants improper authorization to an attacker, enabling them to initiate a remote exploit. Although the exploit has been made public, the authenticity of the vulnerability is yet to be confirmed by Fujifilm. The vendor has expressed doubts about the reported issue, stating that the behaviors in question may be intended or not reproduced.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share