ID

VAR-201403-0046


CVE

CVE-2013-2671


TITLE

Brother MFC-9970CDW Cross-site scripting vulnerability in printer firmware

Trust: 0.8

sources: JVNDB: JVNDB-2013-006194

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware L (1.10) allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) val parameter to admin/admin_main.html; (3) id, (4) val, or (5) arbitrary parameter name (QUERY_STRING) to admin/profile_settings_net.html; or (6) kind or (7) arbitrary parameter name (QUERY_STRING) to fax/general_setup.html, a different vulnerability than CVE-2013-2507 and CVE-2013-2670. Brother MFC-9970CDW The printer firmware contains a cross-site scripting vulnerability. This vulnerability CVE-2013-2507 and CVE-2013-2670 Is a different vulnerability.By any third party, any Web Script or HTML May be inserted. (1) admin/admin_main.html of id Parameters (2) admin/admin_main.html of val Parameters (3) admin/profile_settings_net.html of id Parameters (4) admin/profile_settings_net.html of val Parameters (5) admin/profile_settings_net.html Any parameter name (QUERY_STRING) (6) fax/general_setup.html of kind Parameters (7) fax/general_setup.html Any parameter name (QUERY_STRING). The Brother MFC-9970CDW is a color laser printer device that supports wireless network printing. Because the program fails to properly handle user-supplied input, an attacker can exploit the vulnerability to execute arbitrary script code in the context of the affected browser. This may allow an attacker to steal cookie-based authentication credentials. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ========================================= Brother MFC-9970CDW Firmware 0D Date: Jan. 13, 2013 URL: http://www.cloudscan.me/2013/05/xss-javascript-injection-brother-mfc.html ========================================= Keywords ========================================= XSS, Cross Site Scripting, CWE-79, CAPEC-86, Javascript Injection, Exploit, Zero Day, Brother MFC-9970 CDW CVE-2013-2507, CVE-2013-2670, CVE-2013-2671, CVE-2013-2672, CVE-2013-2673, CVE-2013-2674, CVE-2013-2675, CVE-2013-2676 ========================================= Summary ========================================= A Reflected XSS Bug in the Brother MFC-9970CDW Printer was discovered in January 2013. This document will introduce and discuss the vulnerability and provide Proof-of-Concept (PoC) Zero Day (0D) code examples for Firmware L Version 1.10 Released on July 9, 2012, and prior versions. ========================================= Overview ========================================= Brother Industries, Ltd. is a multinational electronics and electrical equipment company headquartered in Nagoya, Japan. Its products include printers, multifunction printers, sewing machines, large machine tools, label printers, typewriters, fax machines, and other computer-related electronics. Brother distributes its products both under its own name and under OEM agreements with other companies. It produces high-impact color output at impressive print and copy speeds of up to 30ppm and offers flexible connectivity with wireless, Ethernet and USB interfaces. It features a 5" Color Touch Screen display for easy navigation and menu selection. Also, this flagship model offers automatic duplex print/copy/scan/fax and optional high yield toner cartridges to help lower your operating costs \x96 making this all-in-one a smart choice for a business or workgroup. ========================================= The Bug ========================================= Reflected Cross Site Scripting, CWE-79 ========================================= Vulnerable Parameters = id , val, kind + Query String Signature = "><script>alert(1)</script> ========================================= Version Identification ========================================= Brother MFC-9970CDW - Version Identification - Firmware \x93L\x94 Version 1.10 Brother MFC-9970CDW - Version Identification - Firmware \x93G\x94 ========================================= PoC ========================================= PoC URL http://my.vulnerable.printer/admin/admin_main.html?id=websettings"><script> alert(1)</script> ========================================= CVE Information ========================================= CVE-2013-2507 is specific to Firmware G. XSS at: admin/log_to_net.html id parameter fax/copy_settings.html kind parameter CVE-2013-2670 is for the issue that is present in both the Firmware G report and Firmware L. XSS at: admin/admin_main.html name of an arbitrarily assigned URL parameter CVE-2013-2671 is for the XSS issues that are only present in Firmware L. CVEs for Firmware L: Cleartext submission of password CVE-2013-2672 Password field with autocomplete enabled CVE-2013-2673 Cross-domain Referer leakage CVE-2013-2674 Frameable response (Clickjacking) CVE-2013-2675 Private IP addresses disclosed CVE-2013-2676 CVSS 2 Score = 4.5 Timeline Attempt contact via e-mail in January 2013. Call the Toll Free Support Line in March 2013. Callback from Vendor in April 2013. E-mail sent to Vendor in April 2013. VENDOR UNRESPONSIVE Published May 3, 2013 Hoyt LLC Research Public Domain Report http://xss.cx/ ========================================= END ========================================= -----BEGIN PGP SIGNATURE----- Version: 10.2.0.2526 wsBVAwUBUYkKz3z+WcLIygj0AQiVegf/VFskxkdQkqUcqzKXHbTvnHLkkTA8fSgx 1orNQQwxahmpX2f5Jce4zuUz2g+35McwWCKR4kMnOio/9FnWl/w+zqiwmzFqfuHv AIQAD0XXP+vKY/vSF0Bjtg9bUVlkNC4ilmyYVwWS9ycM0HOff3nwXxaZmpkr1Ibb 4Bn4ZeILFYaZYYfj3kM4JSsIuI+gisGmTDg6jMYfZhFDIps5nXeq2vDm34E7Sgx8 nSEOiS9FIq7YSh+ZIWCJE3Olcsx0DUiZuZXVIR4pT8mubB0f6Fx6wOVNQyiT5qNG VQNG1QARkNQFxxuSZD11NtO8mszE+sC8ZBP4VfRjkvJ3c8DecyB5Mg== =Ua1o -----END PGP SIGNATURE-----

Trust: 2.61

sources: NVD: CVE-2013-2671 // JVNDB: JVNDB-2013-006194 // CNVD: CNVD-2014-01795 // BID: 59723 // VULHUB: VHN-62673 // PACKETSTORM: 121553

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-01795

AFFECTED PRODUCTS

vendor:brothermodel:mfc-9970cdwscope:eqversion:l\(1.10\)

Trust: 1.6

vendor:brothermodel:mfc-9970cdwscope:eqversion: -

Trust: 1.0

vendor:brother industrymodel:mfc-9970cdwscope: - version: -

Trust: 0.8

vendor:brother industrymodel:mfc-9970cdwscope:eqversion:l (1.10)

Trust: 0.8

vendor:brothermodel:mfc-9970cdw lscope:eqversion:1.10

Trust: 0.6

vendor:brothermodel:mfc-9970cdw frimware lscope:eqversion:1.10

Trust: 0.3

sources: CNVD: CNVD-2014-01795 // BID: 59723 // JVNDB: JVNDB-2013-006194 // CNNVD: CNNVD-201305-201 // NVD: CVE-2013-2671

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-2671
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-2671
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-01795
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201305-201
value: MEDIUM

Trust: 0.6

VULHUB: VHN-62673
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-2671
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-01795
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-62673
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-01795 // VULHUB: VHN-62673 // JVNDB: JVNDB-2013-006194 // CNNVD: CNNVD-201305-201 // NVD: CVE-2013-2671

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-62673 // JVNDB: JVNDB-2013-006194 // NVD: CVE-2013-2671

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201305-201

TYPE

xss

Trust: 0.7

sources: PACKETSTORM: 121553 // CNNVD: CNNVD-201305-201

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-006194

PATCH

title:Top Pageurl:http://www.brother.com

Trust: 0.8

title:MFC-9970CDWurl:http://brother.jp/product/printer/mfc/mfc9970cdw/index.htm

Trust: 0.8

sources: JVNDB: JVNDB-2013-006194

EXTERNAL IDS

db:NVDid:CVE-2013-2671

Trust: 3.5

db:PACKETSTORMid:121553

Trust: 2.6

db:OSVDBid:93093

Trust: 2.5

db:OSVDBid:93092

Trust: 2.5

db:BIDid:59723

Trust: 1.6

db:XFid:84093

Trust: 1.4

db:JVNDBid:JVNDB-2013-006194

Trust: 0.8

db:CNVDid:CNVD-2014-01795

Trust: 0.6

db:XFid:9970

Trust: 0.6

db:CNNVDid:CNNVD-201305-201

Trust: 0.6

db:VULHUBid:VHN-62673

Trust: 0.1

sources: CNVD: CNVD-2014-01795 // VULHUB: VHN-62673 // BID: 59723 // JVNDB: JVNDB-2013-006194 // PACKETSTORM: 121553 // CNNVD: CNNVD-201305-201 // NVD: CVE-2013-2671

REFERENCES

url:http://packetstormsecurity.com/files/121553/brother-mfc-9970cdw-firmware-0d-cross-site-scripting.html

Trust: 2.5

url:http://osvdb.org/93092

Trust: 2.5

url:http://osvdb.org/93093

Trust: 2.5

url:http://www.cloudscan.me/2013/05/xss-javascript-injection-brother-mfc.html

Trust: 2.1

url:http://osvdb.org/ref/93/brother-mfc9970cdw-firmware-l-110-hoytllc-report.html

Trust: 1.7

url:http://xforce.iss.net/xforce/xfdb/84093

Trust: 1.4

url:http://www.securityfocus.com/bid/59723

Trust: 1.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/84093

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-2671

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-2671

Trust: 0.8

url:http://www.brother.com

Trust: 0.3

url:http://www.brother-usa.com/mfc/modeldetail/4/mfc9970cdw/overview#.uyoaxzdi1ch

Trust: 0.3

url:http://my.vulnerable.printer/admin/admin_main.html?id=websettings"><script>

Trust: 0.1

url:http://xss.cx/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2507

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2671

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2674

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2670

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2676

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2672

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2675

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-2673

Trust: 0.1

sources: CNVD: CNVD-2014-01795 // VULHUB: VHN-62673 // BID: 59723 // JVNDB: JVNDB-2013-006194 // PACKETSTORM: 121553 // CNNVD: CNNVD-201305-201 // NVD: CVE-2013-2671

CREDITS

Hoyt LLC Research

Trust: 0.9

sources: BID: 59723 // CNNVD: CNNVD-201305-201

SOURCES

db:CNVDid:CNVD-2014-01795
db:VULHUBid:VHN-62673
db:BIDid:59723
db:JVNDBid:JVNDB-2013-006194
db:PACKETSTORMid:121553
db:CNNVDid:CNNVD-201305-201
db:NVDid:CVE-2013-2671

LAST UPDATE DATE

2025-04-13T23:14:54.793000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-01795date:2014-03-19T00:00:00
db:VULHUBid:VHN-62673date:2017-08-29T00:00:00
db:BIDid:59723date:2013-05-06T00:00:00
db:JVNDBid:JVNDB-2013-006194date:2014-03-18T00:00:00
db:CNNVDid:CNNVD-201305-201date:2014-03-18T00:00:00
db:NVDid:CVE-2013-2671date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-01795date:2014-03-19T00:00:00
db:VULHUBid:VHN-62673date:2014-03-14T00:00:00
db:BIDid:59723date:2013-05-06T00:00:00
db:JVNDBid:JVNDB-2013-006194date:2014-03-18T00:00:00
db:PACKETSTORMid:121553date:2013-05-08T02:27:54
db:CNNVDid:CNNVD-201305-201date:2013-05-09T00:00:00
db:NVDid:CVE-2013-2671date:2014-03-14T14:55:04.297