SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-13193

Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly.

HIGH 8.8EPSS 3.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
3.09% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
brother/ads-2400n firmware · brother/ads-2800w firmware · brother/ads-3000n firmware · brother/ads-3600w firmware · brother/dcp-1610w firmware · brother/dcp-1610we firmware · brother/dcp-1610wr firmware · brother/dcp-1610wvb firmware · brother/dcp-1612w firmware · brother/dcp-1612we firmware · brother/dcp-1612wr firmware · brother/dcp-1612wvb firmware · brother/dcp-1615nw firmware · brother/dcp-1616nw firmware · brother/dcp-1617nw firmware · brother/dcp-1618w firmware · brother/dcp-1622we firmware · brother/dcp-1623we firmware · brother/dcp-1623wr firmware · brother/dcp-7180dn firmware · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.