PT-2020-9383 · Brother · Dcp-1610We Firmware+5

Published

2020-03-13

·

Updated

2023-08-16

·

CVE-2019-13194

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Brother printers (such as the HL-L8360CDW version 1.20) ads-2400n firmware ads-2800w firmware ads-3000n firmware ads-3600w firmware dcp-1610w firmware dcp-1610we firmware dcp-1610wr firmware dcp-1610wvb firmware
Description: The issue involves different information disclosure vulnerabilities that provide sensitive information to an unauthenticated user who visits a specific URL.
Recommendations: For HL-L8360CDW version 1.20, consider restricting access to the specific URL that discloses sensitive information until a patch is available. For ads-2400n firmware, ads-2800w firmware, ads-3000n firmware, ads-3600w firmware, dcp-1610w firmware, dcp-1610we firmware, dcp-1610wr firmware, and dcp-1610wvb firmware, restrict access to the specific URL that discloses sensitive information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-13194

Affected Products

Hl-L8360Cdw
Ads-2400N Firmware
Ads-2800W Firmware
Ads-3000N Firmware
Ads-3600W Firmware
Dcp-1610We Firmware