CVE-2024-47850: High severity Apple CUPS vulnerability
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than <a href="https://access.redhat.com/security/cve/CVE-2024-47176">CVE-2024-47176</a>. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)
Other sources
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47850?
CVE-2024-47850 is considered a high-severity vulnerability due to its potential for abuse in sending arbitrary HTTP requests.
How do I fix CVE-2024-47850?
To fix CVE-2024-47850, update to CUPS version 2.5b1 or later as it addresses this vulnerability.
What systems are affected by CVE-2024-47850?
CVE-2024-47850 affects versions of Apple CUPS prior to 2.5b1.
What are the risks of CVE-2024-47850?
The risks of CVE-2024-47850 include potential unauthorized requests being sent to arbitrary destinations, leading to data exposure or service disruption.
Is CVE-2024-47850 a remote vulnerability?
Yes, CVE-2024-47850 can be exploited remotely via IPP UDP packets.