HomeSecuritySecurity flaw in Brother printers exposes admin passwords

Security flaw in Brother printers exposes admin passwords

More than 740 printer models (689 from Brother and 53 from other manufacturers such as Fujifilm, Toshiba and Konica Minolta)have a serious security flaw: default administrator passwords that can be predicted and exploited by remote attackers. Most worryingly? The problem cannot be fixed by updating the firmware on existing devices.

Brother printers

The vulnerability has been recorded as CVE-2024-51978 and is part of a larger set of eight vulnerabilities identified by researchers Rapid7after extensive research into Brother devices.

CVEDescriptionAffected ServiceCVSS
CVE-2024-51977An unauthorized attacker can leak sensitive informationHTTP (Port 80), HTTPS (Port 443), IPP (Port 631)5.3
CVE-2024-51978An unauthorized attacker can create the device's default administrator passwordHTTP (Port 80), HTTPS (Port 443), IPP (Port 631)9.8
CVE-2024-51979An authorized attacker can trigger a stack based buffer overflowHTTP (Port 80), HTTPS (Port 443), IPP (Port 631)7.2
CVE-2024-51980An unauthorized attacker can force the device to open a TCP connectionWeb Services over HTTP (Port 80)5.3
CVE-2024-51981An unauthorized attacker can force the device to execute an arbitrary HTTP requestWeb Services over HTTP (Port 80)5.3
CVE-2024-51982An unauthorized attacker can cause the device to stop workingPJL (Port 9100)7.5
CVE-2024-51983An unauthorized attacker can cause the device to stop workingWeb Services over HTTP (Port 80)7.5
CVE-2024-51984An authorized attacker can reveal the password of a configured external serviceLDAP, FTP6.8

The security hole is extremely dangerous, as it can be exploited in combination with other vulnerabilities to find the administrator password, take control of the device, execute arbitrary code, and even interfere with the network to which the devices are connected.

See also: IBM i vulnerability allows privilege escalation

Not all of the defects affect all Brother printer models, but 46 Fujifilm, 6 Konica Minolta, 5 Ricoh , and 2 Toshiba models.

The danger behind the default password

The heart of the problem lies in the way the default passwords are generated. These are generated at the factory when the printers are manufactured, using an algorithm based on the serial number of each device. Although seemingly secure, the algorithm is in practice easily reversible.

According to Rapid7's technical analysis, the code generation process follows these steps:

  1. Get the first 16 characters of the serial number.
  2. Add 8 bytes from a static “salt” table.
  3. Hash using the SHA256 algorithm.
  4. Encoding the Hash with Base64.
  5. Selecting the first 8 characters and replacing some letters with special characters.

How attackers gain access to Brother printers

Attackers can leak the serial number of the target printer using various methods or by exploiting CVE-2024-51977. From there, they apply the now-known algorithm to generate the default administrator password and gain access to the device's configuration environment as an administrator

See also: CISA added three new vulnerabilities to the KEV List

Once the attacker logs in as an administrator, the exploitation possibilities are extensive:

  • Resetting the device
  • Access saved scans and address books
  • Exploiting CVE-2024-51979 for remote code execution
  • Using CVE-2024-51984 to collect credentials

Apocalyptic research and its… limits

Rapid7 began the responsible disclosure process in May 2024 , with the assistance of JPCERT /CC , to coordinate updates from other manufacturers. While most vendors—including Brother, Fujifilm, Konica Minolta, Ricoh, and Toshiba—have issued firmware fixes , CVE -2024-51978 remains a special case.

Security flaw in Brother printers exposes admin passwords

This vulnerability stems from the way devices are manufactured and default passwords. Therefore, all devices manufactured before the issue was discovered are considered vulnerable unless users have manually changed the administrator password.

As Rapid7 points out, Brother has acknowledged that the vulnerability cannot be fully addressed through a firmware update, as it requires modification of the manufacturing process itself.

What users can do

For owners of vulnerable Brother printer models, it is imperative to immediately change the default admin password . Immediately after, the latest available software updates should be applied .

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Citrix: NetScaler vulnerability used for DoS attacks

Additionally, it is recommended to restrict access to the printer's admin interfaces via insecure protocols and external networks. Finally, manufacturers have already published detailed security bulletins, with instructions and countermeasures, available for affected models from Brother, Konica Minolta, Fujifilm, Ricoh and Toshiba.

The situation described is serious and revealing of the long-standing security problems associated with devices IoT and printers, which are often neglected from a security perspective by both manufacturers and users.

Printers, scanners, and other connected devices are often not treated as potentially dangerous entry points, when in fact they are easily accessible and with inadequate authentication.

Requiring the average user to change their password and understand the technical details themselves is insufficient. Most users don’t even know about it or don’t have the skills to do it properly. Security should be “by design” and not an afterthought

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS