Vulnerability Description
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Brother | Mfc Firmware | - |
| Brother | Mfc-8710Dw | - |
| Brother | Mfc-9130Cw | - |
| Brother | Mfc-9330Cdw | - |
| Brother | Mfc-9340Cdw | - |
| Brother | Mfc-J3720 | - |
| Brother | Mfc-J4420Dw | - |
| Brother | Mfc-J4620Dw | - |
| Brother | Mfc-J5620Dw | - |
| Brother | Mfc-J5910Dw | - |
| Brother | Mfc-J6520Dw | - |
| Brother | Mfc-J6720Dw | - |
| Brother | Mfc-J6920Dw | - |
| Brother | Mfc-J6973Cdw | - |
| Brother | Mfc-L2700Dw | - |
| Brother | Mfc-L2720Dw | - |
| Brother | Mfc-L2740Dw | - |
| Brother | Mfc-L8600Cdw | - |
| Brother | Mfc-L8850Cdw | - |
| Brother | Mfc-L9550Cdw | - |
Related Weaknesses (CWE)
References
- https://cxsecurity.com/blad/WLB-2017040064
- https://www.exploit-db.com/exploits/41863/
- https://cxsecurity.com/blad/WLB-2017040064
- https://www.exploit-db.com/exploits/41863/
FAQ
What is CVE-2017-7588?
CVE-2017-7588 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW ...
How severe is CVE-2017-7588?
CVE-2017-7588 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-7588?
Check the references section above for vendor advisories and patch information. Affected products include: Brother Mfc Firmware, Brother Mfc-8710Dw, Brother Mfc-9130Cw, Brother Mfc-9330Cdw, Brother Mfc-9340Cdw.