Vulnerabilities (CVE)

Filtered by vendor Brother Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13193 1 Brother 600 Ads-2400n, Ads-2400n Firmware, Ads-2800w and 597 more 2023-08-16 9.0 HIGH 8.8 HIGH
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.
CVE-2019-13194 1 Brother 600 Ads-2400n, Ads-2400n Firmware, Ads-2800w and 597 more 2023-08-16 5.0 MEDIUM 7.5 HIGH
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.
CVE-2023-29984 3 Brother, Fujifilm, Toshibatec 432 Dcp-1610w, Dcp-1610w Firmware, Dcp-1610we and 429 more 2023-08-07 N/A 7.5 HIGH
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
CVE-2017-2244 1 Brother 2 Mfc-j960dwn, Mfc-j960dwn Firmware 2021-09-10 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2013-2676 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2020-02-12 5.0 MEDIUM 7.5 HIGH
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.
CVE-2013-2672 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2020-02-05 5.0 MEDIUM 7.5 HIGH
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
CVE-2013-2674 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2020-02-05 5.0 MEDIUM 7.5 HIGH
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.
CVE-2017-16249 1 Brother 2 Dcp-j132w, Dcp-j132w Firmware 2019-10-03 7.8 HIGH 7.5 HIGH
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
CVE-2017-12568 1 Brother 2 Dcp-j132w, Dcp-j132w Firmware 2019-10-03 7.8 HIGH 7.5 HIGH
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its network connection) by sending a large amount of HTTP packets.