Vulnerability Description
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fujifilm | Docuprint M265 Z Firmware | < n |
| Fujifilm | Docuprint M265 Z | - |
| Fujifilm | Docuprint M268 Z Firmware | < l |
| Fujifilm | Docuprint M268 Z | - |
| Fujifilm | Docuprint M225 Z Firmware | < n |
| Fujifilm | Docuprint M225 Z | - |
| Fujifilm | Docuprint M225 Dw Firmware | < n |
| Fujifilm | Docuprint M225 Dw | - |
| Fujifilm | Docuprint M268 Dw Firmware | < l |
| Fujifilm | Docuprint M268 Dw | - |
| Fujifilm | Docuprint P265 Dw Firmware | < 1.21 |
| Fujifilm | Docuprint P265 Dw | - |
| Fujifilm | Docuprint P268 Dw Firmware | < 1.21 |
| Fujifilm | Docuprint P268 Dw | - |
| Fujifilm | Docuprint P268 D Firmware | < 1.21 |
| Fujifilm | Docuprint P268 D | - |
| Fujifilm | Docuprint P225 D Firmware | < 1.17 |
| Fujifilm | Docuprint P225 D | - |
| Fujifilm | Docuprint M118 Z Firmware | < l |
| Fujifilm | Docuprint M118 Z | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU93767756/index.htmlThird Party Advisory
- https://support.brother.com/g/b/faqend.aspx?c=us&lang=en&prod=group2&faqid=faq00
- https://support.brother.com/g/s/security/en/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.Vendor Advisory
- https://jvn.jp/en/vu/JVNVU93767756/index.htmlThird Party Advisory
- https://support.brother.com/g/b/faqend.aspx?c=us&lang=en&prod=group2&faqid=faq00
- https://support.brother.com/g/s/security/en/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.Vendor Advisory
FAQ
What is CVE-2023-29984?
CVE-2023-29984 is a vulnerability with a CVSS score of 7.5 (HIGH). Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to ...
How severe is CVE-2023-29984?
CVE-2023-29984 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29984?
Check the references section above for vendor advisories and patch information. Affected products include: Fujifilm Docuprint M265 Z Firmware, Fujifilm Docuprint M265 Z, Fujifilm Docuprint M268 Z Firmware, Fujifilm Docuprint M268 Z, Fujifilm Docuprint M225 Z Firmware.