Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Very Low
CVE-2017-16249
Disclosure Date: November 10, 2017 (last updated November 26, 2024)
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
0
Attacker Value
Unknown
CVE-2023-29984
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
0
Attacker Value
Unknown
CVE-2019-13193
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.
0
Attacker Value
Unknown
CVE-2019-13192
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.
0
Attacker Value
Unknown
CVE-2019-13194
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.
0
Attacker Value
Unknown
CVE-2019-13946
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit
internal resource allocation when multiple legitimate diagnostic package
requests are sent to the DCE-RPC interface.
This could lead to a denial of service condition due to lack of memory
for devices that include a vulnerable version of the stack.
The security vulnerability could be exploited by an attacker with network
access to an affected device. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise the availability of the device.
0
Attacker Value
Unknown
CVE-2019-10936
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
Affected devices improperly handle large amounts of specially crafted UDP packets.
This could allow an unauthenticated remote attacker to trigger a denial of service condition.
0
Attacker Value
Unknown
CVE-2019-10923
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
0
Attacker Value
Unknown
CVE-2017-12741
Disclosure Date: December 26, 2017 (last updated July 10, 2024)
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
0
Attacker Value
Unknown
CVE-2017-12568
Disclosure Date: August 06, 2017 (last updated November 26, 2024)
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its network connection) by sending a large amount of HTTP packets.
0