PT-2017-3094 · Brother · Hl-3140Cw+28

Patryk Bogdan

+1

·

Published

2017-04-11

·

Updated

2017-08-16

·

CVE-2017-7588

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Brother printer software versions (affected versions not specified) Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W
Description The vulnerability is related to the authentication procedure in Brother printer software. After a failed login attempt, the HTTP response includes a valid AuthCookie, which can be exploited by a remote attacker to gain access to the device.
Recommendations For each of the affected models, consider disabling the authentication mechanism until a patch is available. Restrict access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02472
CVE-2017-7588

Affected Products

Ads-1000W
Ads-1500W
Ads-2500W
Dcp-L2520Dw
Dcp-L2540Dw
Hl-3140Cw
Hl-3170Cdw
Hl-3180Cdw
Hl-L2380Dw
Hl-L8350Cdw
Mfc-8710Dw
Mfc-9130Cw
Mfc-9330Cdw
Mfc-9340Cdw
Mfc-J3720
Mfc-J4420Dw
Mfc-J4620Dw
Mfc-J5620Dw
Mfc-J5910Dw
Mfc-J6520Dw
Mfc-J6720Dw
Mfc-J6920Dw
Mfc-J6973Cdw
Mfc-L2700Dw
Mfc-L2720Dw
Mfc-L2740Dw
Mfc-L8600Cdw
Mfc-L8850Cdw
Mfc-L9550Cdw