CVE-2024-12782

HIGH

Fujifilm Business Innovation Apeos C3070-24.8.28 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains that "during technical verification it is not possible to reproduce any active actions like reboots which were mentioned in the original researcher disclosure."

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.288958
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.288958
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.458897

Scores

CVSS v3 7.3
EPSS 0.0071
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (50)
Fujifilm Business Innovation/Apeos C3070 22.1.0
Fujifilm Business Innovation/Apeos C3070 22.1.1
Fujifilm Business Innovation/Apeos C3070 22.1.10
Fujifilm Business Innovation/Apeos C3070 22.1.11
Fujifilm Business Innovation/Apeos C3070 22.1.12
Fujifilm Business Innovation/Apeos C3070 22.1.13
Fujifilm Business Innovation/Apeos C3070 22.1.14
Fujifilm Business Innovation/Apeos C3070 22.1.15
Fujifilm Business Innovation/Apeos C3070 22.1.16
Fujifilm Business Innovation/Apeos C3070 22.1.17
... and 40 more
Published Dec 19, 2024
Tracked Since Feb 18, 2026