Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7588


On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.


Published

2017-04-12T10:59:00.337

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System brother mfc_firmware - Yes
Hardware brother mfc-8710dw - No
Hardware brother mfc-9130cw - No
Hardware brother mfc-9330cdw - No
Hardware brother mfc-9340cdw - No
Hardware brother mfc-j3720 - No
Hardware brother mfc-j4420dw - No
Hardware brother mfc-j4620dw - No
Hardware brother mfc-j5620dw - No
Hardware brother mfc-j5910dw - No
Hardware brother mfc-j6520dw - No
Hardware brother mfc-j6720dw - No
Hardware brother mfc-j6920dw - No
Hardware brother mfc-j6973cdw - No
Hardware brother mfc-l2700dw - No
Hardware brother mfc-l2720dw - No
Hardware brother mfc-l2740dw - No
Hardware brother mfc-l8600cdw - No
Hardware brother mfc-l8850cdw - No
Hardware brother mfc-l9550cdw - No
Operating System brother dcp_firmware - Yes
Hardware brother dcp-l2520dw - No
Hardware brother dcp-l2540dw - No
Operating System brother ads_firmware - Yes
Hardware brother ads-1000w - No
Hardware brother ads-1500w - No
Hardware brother ads-2500w - No
Operating System brother hl_firmware - Yes
Hardware brother hl-3140cw - No
Hardware brother hl-3170cdw - No
Hardware brother hl-3180cdw - No
Hardware brother hl-l2380dw - No
Hardware brother hl-l8350cdw - No

References