Vulnerabilities > Brother > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-11 CVE-2023-29984 NULL Pointer Dereference vulnerability in multiple products
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3.
network
low complexity
fujifilm toshibatec brother CWE-476
7.5
2020-03-13 CVE-2019-13194 Missing Authentication for Critical Function vulnerability in Brother products
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.
network
low complexity
brother CWE-306
7.5
2020-03-13 CVE-2019-13193 Out-of-bounds Write vulnerability in Brother products
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly.
network
low complexity
brother CWE-787
8.8
2020-02-04 CVE-2013-2676 Information Exposure vulnerability in Brother Mfc-9970Cdw Firmware 1.10
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.
network
low complexity
brother CWE-200
7.5
2020-02-03 CVE-2013-2674 Information Exposure vulnerability in Brother Mfc-9970Cdw Firmware 1.10
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.
network
low complexity
brother CWE-200
7.5
2020-02-03 CVE-2013-2672 Insufficiently Protected Credentials vulnerability in Brother Mfc-9970Cdw Firmware 1.10
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
network
low complexity
brother CWE-522
7.5
2017-11-10 CVE-2017-16249 Unspecified vulnerability in Brother Dcp-J132W Firmware 1.20
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error.
network
low complexity
brother
7.5
2017-08-06 CVE-2017-12568 Unspecified vulnerability in Brother Dcp-J132W Firmware 1.20
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its network connection) by sending a large amount of HTTP packets.
network
low complexity
brother
7.5
2017-07-07 CVE-2017-2244 Cross-Site Request Forgery (CSRF) vulnerability in Brother Mfc-J960Dwn Firmware D
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
brother CWE-352
8.8