Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16249

Опубликовано: 10 нояб. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Средний

Описание

The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:brother:dcp-j132w_firmware:*:*:*:*:*:*:*:*
Версия до 1.20 (включая)
cpe:2.3:h:brother:dcp-j132w:-:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.67301
Средний

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.

EPSS

Процентиль: 99%
0.67301
Средний

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

NVD-CWE-noinfo