CVE-2024-51983

HIGH

Web Services < unknown - DoS

Title source: llm
STIX 2.1

Description

An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device.

Scores

CVSS v3 7.5
EPSS 0.0206
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1286
Status published
Products (50)
Brother Industries, Ltd/ADS-1250W < R(3.75)
Brother Industries, Ltd/ADS-1350W < C(1.06)
Brother Industries, Ltd/ADS-1700W < R(3.75)
Brother Industries, Ltd/ADS-1800W < C(1.06)
Brother Industries, Ltd/ADS-2400N < T
Brother Industries, Ltd/ADS-2700W < M(4.28)
Brother Industries, Ltd/ADS-2700We < P(2.28)
Brother Industries, Ltd/ADS-2800W < T
Brother Industries, Ltd/ADS-3000N < T
Brother Industries, Ltd/ADS-3300W < P(2.28)
... and 40 more
Published Jun 25, 2025
Tracked Since Feb 18, 2026