CVE-2017-16249
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
HIGH
7,8
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: complete
Description
AI Translation Available
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,6730
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
Exploit
Debut Embedded HTTPd 1.20 - Denial of Service
Debut Embedded HTTPd 1.20 - Denial of Service
View Exploit Code →
Operating System
Dcp-J132W Firmware by Brother
Version Range Affected
To
1.20
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:brother:dcp-j132w_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://packetstormsecurity.com/files/144908/Debut-Embedded-httpd-1.20-Denial-Of…
https://www.exploit-db.com/exploits/43119/
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-017…
https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerabi…
http://packetstormsecurity.com/files/144908/Debut-Embedded-httpd-1.20-Denial-Of…
https://www.exploit-db.com/exploits/43119/
https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-017…
https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerabi…