PT-2017-3094 · Brother · Hl-3140Cw+28
Patryk Bogdan
+1
·
Published
2017-04-11
·
Updated
2017-08-16
·
CVE-2017-7588
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Brother printer software versions (affected versions not specified)
Affected models are:
MFC-J6973CDW
MFC-J4420DW
MFC-8710DW
MFC-J4620DW
MFC-L8850CDW
MFC-J3720
MFC-J6520DW
MFC-L2740DW
MFC-J5910DW
MFC-J6920DW
MFC-L2700DW
MFC-9130CW
MFC-9330CDW
MFC-9340CDW
MFC-J5620DW
MFC-J6720DW
MFC-L8600CDW
MFC-L9550CDW
MFC-L2720DW
DCP-L2540DW
DCP-L2520DW
HL-3140CW
HL-3170CDW
HL-3180CDW
HL-L8350CDW
HL-L2380DW
ADS-2500W
ADS-1000W
ADS-1500W
Description
The vulnerability is related to the authentication procedure in Brother printer software. After a failed login attempt, the HTTP response includes a valid
AuthCookie, which can be exploited by a remote attacker to gain access to the device.Recommendations
For each of the affected models, consider disabling the authentication mechanism until a patch is available.
Restrict access to the device to minimize the risk of exploitation.
Avoid using the device until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ads-1000W
Ads-1500W
Ads-2500W
Dcp-L2520Dw
Dcp-L2540Dw
Hl-3140Cw
Hl-3170Cdw
Hl-3180Cdw
Hl-L2380Dw
Hl-L8350Cdw
Mfc-8710Dw
Mfc-9130Cw
Mfc-9330Cdw
Mfc-9340Cdw
Mfc-J3720
Mfc-J4420Dw
Mfc-J4620Dw
Mfc-J5620Dw
Mfc-J5910Dw
Mfc-J6520Dw
Mfc-J6720Dw
Mfc-J6920Dw
Mfc-J6973Cdw
Mfc-L2700Dw
Mfc-L2720Dw
Mfc-L2740Dw
Mfc-L8600Cdw
Mfc-L8850Cdw
Mfc-L9550Cdw