Brother DCP-J132W Printer
Platform Information | https://support.brother.com/g/b/spec.aspx?c=eu_ot&lang=en&prod=dcpj132w_eu |
---|---|
Search Engine | Search on Google |
End of Sales | Yes more info |
End of Support | - |
Wired Connection | Yes |
Wireless Connection | Yes |
Fingerprinting Source | HTTP NIC VENDOR |
Added at | Nov 05, 2019 |
Manufacturer Name | Brother Industries Ltd. |
Homepage | http://www.brother.com/index.htm |
Headquarters | Japan |
Business Status | Ongoing |
Platform’s Common Vulnerabilities and Exposures (CVE) | ||
---|---|---|
CVE-ID
Severity v3.0
Severity v2.0
Description
|
||
CVE-2017-16249
11/10/2017 HIGH
HIGH
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
|
||
CVE-2017-12568
08/06/2017 HIGH
HIGH
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its network connection) by sending a large amount of HTTP packets.
|
Manufacturer’s Common Vulnerabilities and Exposures (CVE) | ||
---|---|---|
CVE-ID
Severity v3.0
Severity v2.0
Description
|
||
CVE-2018-11581
06/01/2018 MEDIUM
LOW
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.
|
||
CVE-2017-16249
11/10/2017 HIGH
HIGH
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
|
||
CVE-2017-12568
08/06/2017 HIGH
HIGH
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its network connection) by sending a large amount of HTTP packets.
|
||
CVE-2017-7588
04/12/2017 CRITICAL
HIGH
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.
|
||
CVE-2015-1056
01/16/2015 MEDIUM
Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW printer with firmware before L allows remote attackers to inject arbitrary web script or HTML via the url parameter to general/status.html and possibly other pages.
|