CVE-2023-29984
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.94%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- fujifilm/docuprint m265 z firmware · fujifilm/docuprint m268 z firmware · fujifilm/docuprint m225 z firmware · fujifilm/docuprint m225 dw firmware · fujifilm/docuprint m268 dw firmware · fujifilm/docuprint p265 dw firmware · fujifilm/docuprint p268 dw firmware · fujifilm/docuprint p268 d firmware · fujifilm/docuprint p225 d firmware · fujifilm/docuprint m118 z firmware · fujifilm/docuprint m118 w firmware · fujifilm/docuprint m115 z firmware · fujifilm/docuprint m115 fw firmware · fujifilm/docuprint m115 w firmware · fujifilm/docuprint p118 w firmware · fujifilm/docuprint p115 w firmware · toshibatec/e-studio 302dnf firmware · toshibatec/e-studio 301dn firmware · brother/dcp-1610w firmware · brother/dcp-1610we firmware · +40 more
- Source
- cve@mitre.org
References
- https://jvn.jp/en/vu/JVNVU93767756/index.htmlThird Party Advisory
- https://support.brother.com/g/b/faqend.aspx?c=us&lang=en&prod=group2&faqid=faq00100793_000
- https://support.brother.com/g/s/security/en/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU93767756/index.htmlThird Party Advisory
- https://support.brother.com/g/b/faqend.aspx?c=us&lang=en&prod=group2&faqid=faq00100793_000
- https://support.brother.com/g/s/security/en/
- https://www.fujifilm.com/fbglobal/eng/company/news/notice/2023/browser_announce.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.