[Japanese]

JVNDB-2023-002270

Null pointer dereference vulnerability in multiple printers and MFPs which implement BROTHER debut web server

Overview

Multiple printers and MFPs (multifunction printers) which implement Brother debut web server contain a null pointer dereference vulnerability (CWE-476, CVE-2023-29984).

Darren Johnson directly reported this vulnerability to BROTHER INDUSTRIES, LTD. and FUJIFILM Business Innovation Corp., and both vendors reported this case to JPCERT/CC to request the coordination between the reporter and the susceptible multiple vendors.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: Low
Affected Products


Brother Industries
  • debutwebserver Specific products/models/versions which implement debut web server 1.20 or 1.30

As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors.
Impact

Processing a specially crafted request may lead the affected products to a denial-of-service (DoS) condition.
Solution

[Update the firmware]
Apply the appropriate firmware update according to the information provided by the respective vendors.
For the details of the updates, refer to the information provided by the respective vendors from [Vendor Status] section.
Vendor Information

Brother Industries TOSHIBA TEC FUJIFILM Business Innovation Corp. (former Fuji Xerox Co., Ltd.)
CWE (What is CWE?)

  1. NULL Pointer Dereference(CWE-476) [Other]
CVE (What is CVE?)

  1. CVE-2023-29984
References

  1. JVN : JVNVU#93767756
  2. National Vulnerability Database (NVD) : CVE-2023-29984
Revision History

  • [2023/06/30]
      Web page was published
  • [2024/04/22]
      References : Content was added