CRITICAL · 9.8

CVE-2017-7588

On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW ...

Vulnerability Description

On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BrotherMfc Firmware-
BrotherMfc-8710Dw-
BrotherMfc-9130Cw-
BrotherMfc-9330Cdw-
BrotherMfc-9340Cdw-
BrotherMfc-J3720-
BrotherMfc-J4420Dw-
BrotherMfc-J4620Dw-
BrotherMfc-J5620Dw-
BrotherMfc-J5910Dw-
BrotherMfc-J6520Dw-
BrotherMfc-J6720Dw-
BrotherMfc-J6920Dw-
BrotherMfc-J6973Cdw-
BrotherMfc-L2700Dw-
BrotherMfc-L2720Dw-
BrotherMfc-L2740Dw-
BrotherMfc-L8600Cdw-
BrotherMfc-L8850Cdw-
BrotherMfc-L9550Cdw-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-7588?

CVE-2017-7588 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW ...

How severe is CVE-2017-7588?

CVE-2017-7588 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-7588?

Check the references section above for vendor advisories and patch information. Affected products include: Brother Mfc Firmware, Brother Mfc-8710Dw, Brother Mfc-9130Cw, Brother Mfc-9330Cdw, Brother Mfc-9340Cdw.