CVE-2017-7588
Published Apr 12, 2017
Last updated 7 years ago
Overview
- Description
- On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:brother:mfc_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E75786C-418A-4C7D-9516-5328931391B9" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:brother:mfc-8710dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "063EFDCB-ACA5-48CC-8ACB-B4C35AE82DE5" }, { "criteria": "cpe:2.3:h:brother:mfc-9130cw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "620943CE-02CE-490D-9D92-6A46F591A002" }, { "criteria": "cpe:2.3:h:brother:mfc-9330cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6F94C339-B174-4F36-AAC4-6F7B676E0A54" }, { "criteria": "cpe:2.3:h:brother:mfc-9340cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E8096B8B-E830-4008-B970-11F7F86531DC" }, { "criteria": "cpe:2.3:h:brother:mfc-j3720:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1E30AFC7-51C8-4C89-81BD-5BE8E10FB789" }, { "criteria": "cpe:2.3:h:brother:mfc-j4420dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2EB4E3BE-698A-47D6-A4F4-B9CAA371ADCF" }, { "criteria": "cpe:2.3:h:brother:mfc-j4620dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EE4FF760-1267-4281-B1D0-80BBAFED9CDD" }, { "criteria": "cpe:2.3:h:brother:mfc-j5620dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8F34C514-2738-4206-8B23-2AC7EB0E900B" }, { "criteria": "cpe:2.3:h:brother:mfc-j5910dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FFB8BFDB-0796-455F-8F0A-42A5885C1404" }, { "criteria": "cpe:2.3:h:brother:mfc-j6520dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5A349B90-B721-42FE-B136-726093F8FCD9" }, { "criteria": "cpe:2.3:h:brother:mfc-j6720dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B0358966-552E-47B8-AAA9-8922609625E2" }, { "criteria": "cpe:2.3:h:brother:mfc-j6920dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "66C3D9CC-7C78-4171-95D7-7FD4CD6F0387" }, { "criteria": "cpe:2.3:h:brother:mfc-j6973cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "ECA24CE5-445C-4980-B46A-B7715810BC7F" }, { "criteria": "cpe:2.3:h:brother:mfc-l2700dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36099941-3EBD-44B5-8452-093EF433642E" }, { "criteria": "cpe:2.3:h:brother:mfc-l2720dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C3B00252-5D1C-4922-A223-92958F945DB8" }, { "criteria": "cpe:2.3:h:brother:mfc-l2740dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6079C730-2332-429C-9833-BEB7081D2C92" }, { "criteria": "cpe:2.3:h:brother:mfc-l8600cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6DD70CBD-FF0C-4987-90B3-357F1F6D60A2" }, { "criteria": "cpe:2.3:h:brother:mfc-l8850cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EDCBA36B-4BE4-4C0D-ABDE-76A2A7B8E9FA" }, { "criteria": "cpe:2.3:h:brother:mfc-l9550cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "39596AFD-DA7E-4DED-B132-888CD804F44F" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:brother:dcp_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B17165B-7D42-4DF0-9C26-638C37904476" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:brother:dcp-l2520dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0445551D-01CA-435B-B4F4-79022C18237F" }, { "criteria": "cpe:2.3:h:brother:dcp-l2540dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "207F0E9F-29B1-4AEC-B0F1-14424060D61D" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:brother:ads_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0D9D4CB-E9E8-47C3-9826-1D2F976F864F" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:brother:ads-1000w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7F2240DC-9A63-49EA-9BC6-C12111839753" }, { "criteria": "cpe:2.3:h:brother:ads-1500w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4064DB43-1CD0-4149-85EC-AFD7B1CD062B" }, { "criteria": "cpe:2.3:h:brother:ads-2500w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4CD13640-29B4-4784-9A61-3922ECB6E0FA" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:brother:hl_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B89B169-2D03-499C-9022-656124B5E8D8" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:brother:hl-3140cw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A36ADEE6-20CB-42AA-9E2F-F349DACAD75A" }, { "criteria": "cpe:2.3:h:brother:hl-3170cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3BD6C1B8-1FAF-4A20-BDEA-B0377295DDDD" }, { "criteria": "cpe:2.3:h:brother:hl-3180cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB5A15D7-1C22-4C7C-927D-58A5451F6511" }, { "criteria": "cpe:2.3:h:brother:hl-l2380dw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FF710C62-026C-4DA1-AD1E-AB95EC2BA9B7" }, { "criteria": "cpe:2.3:h:brother:hl-l8350cdw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "024B4793-D380-4C28-8C83-0F37F3F5A0D1" } ], "operator": "OR" } ], "operator": "AND" } ]