First published: Fri Mar 14 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware G (1.03) allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/log_to_net.html or (2) kind parameter to fax/copy_settings.html, a different vulnerability than CVE-2013-2670 and CVE-2013-2671.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Brother Mfc-9970cdw Firmware | =g\(1.03\) | |
Brother MFC-9970CDW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2507 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-2507, you should update the firmware of the Brother MFC-9970CDW printer to the latest version provided by Brother.
CVE-2013-2507 can be exploited by injecting arbitrary web scripts through the id parameter in admin/log_to_net.html or the kind parameter in fax/copy_settings.html.
The vulnerability affects users of the Brother MFC-9970CDW printer with firmware version g(1.03).
A known workaround for CVE-2013-2507 includes restricting access to the printer's web interface to trusted networks only.