CVE-2017-16249
Debut Embedded HTTPd 1.20 - Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
El servidor http incorporado de Debut contiene una denegación de servicio explotable remotamente donde una única solicitud POST HTTP malformada puede hacer que el servidor se bloquee hasta que finalmente responda (en aproximadamente 300 segundos) con un error HTTP 500. Mientras el servidor está colgado, los trabajos de impresión por medio de la red están bloqueados y la interfaz web es inaccesible. Un atacante puede enviar continuamente esta solicitud malformada para mantener inaccesible el dispositivo para el tráfico legítimo.
The Debut embedded HTTP server <= 1.20 on Brother printers allows for a Denial of Service (DoS) condition via a crafted HTTP request. The printer will be unresponsive from HTTP and printing requests for ~300 seconds. After which, the printer will start responding again.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-31 CVE Reserved
- 2017-11-07 CVE Published
- 2023-05-12 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerability-in-Brother-Printers/?page=1&year=0&month=0&LangType=1033 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Brother Search vendor "Brother" | Dcp-j132w Firmware Search vendor "Brother" for product "Dcp-j132w Firmware" | <= 1.20 Search vendor "Brother" for product "Dcp-j132w Firmware" and version " <= 1.20" | - |
Affected
| in | Brother Search vendor "Brother" | Dcp-j132w Search vendor "Brother" for product "Dcp-j132w" | - | - |
Safe
|