CVE-2017-7588

On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:brother:mfc_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:brother:mfc-8710dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-9130cw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-9330cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-9340cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j3720:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j4420dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j4620dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j5620dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j5910dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j6520dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j6720dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j6920dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-j6973cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l2700dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l2720dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l2740dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l8600cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l8850cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:mfc-l9550cdw:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:brother:dcp_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:brother:dcp-l2520dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:dcp-l2540dw:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:brother:ads_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:brother:ads-1000w:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:ads-1500w:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:ads-2500w:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:brother:hl_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:brother:hl-3140cw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:hl-3170cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:hl-3180cdw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:hl-l2380dw:-:*:*:*:*:*:*:*
cpe:2.3:h:brother:hl-l8350cdw:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-04-12 10:59

Updated : 2024-02-28 15:44


NVD link : CVE-2017-7588

Mitre link : CVE-2017-7588

CVE.ORG link : CVE-2017-7588


JSON object : View

Products Affected

brother

  • ads-1500w
  • mfc-9340cdw
  • mfc-j3720
  • mfc-j5620dw
  • mfc-l2740dw
  • mfc-j6973cdw
  • ads-1000w
  • mfc-l8850cdw
  • mfc-j6920dw
  • mfc-j6720dw
  • hl_firmware
  • hl-l8350cdw
  • hl-3170cdw
  • mfc-l9550cdw
  • mfc-j5910dw
  • hl-3180cdw
  • mfc_firmware
  • ads-2500w
  • hl-l2380dw
  • mfc-l2720dw
  • mfc-8710dw
  • mfc-9130cw
  • mfc-9330cdw
  • mfc-j4420dw
  • mfc-l2700dw
  • dcp_firmware
  • dcp-l2540dw
  • mfc-j6520dw
  • mfc-l8600cdw
  • hl-3140cw
  • dcp-l2520dw
  • ads_firmware
  • mfc-j4620dw
CWE
CWE-287

Improper Authentication