CVE-2019-13192
Last modified
CVE-2019-13192 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.. EPSS estimates a 3.73% chance of exploitation in the next 30 days.
Description
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Brother | Ads-2400n Firmware | All versions |
| Brother | Ads-2800w Firmware | All versions |
| Brother | Ads-3000n Firmware | All versions |
| Brother | Ads-3600w Firmware | All versions |
| Brother | Dcp-1610w Firmware | All versions |
| Brother | Dcp-1610we Firmware | All versions |
| Brother | Dcp-1610wr Firmware | All versions |
| Brother | Dcp-1610wvb Firmware | All versions |
| Brother | Dcp-1612w Firmware | All versions |
| Brother | Dcp-1612we Firmware | All versions |
| Brother | Dcp-1612wr Firmware | All versions |
| Brother | Dcp-1612wvb Firmware | All versions |
| Brother | Dcp-1615nw Firmware | All versions |
| Brother | Dcp-1616nw Firmware | All versions |
| Brother | Dcp-1617nw Firmware | All versions |
| Brother | Dcp-1618w Firmware | All versions |
| Brother | Dcp-1622we Firmware | All versions |
| Brother | Dcp-1623we Firmware | All versions |
| Brother | Dcp-1623wr Firmware | All versions |
| Brother | Dcp-7180dn Firmware | All versions |
| Brother | Dcp-7195dw Firmware | All versions |
| Brother | Dcp-9030cdn Firmware | All versions |
| Brother | Dcp-B7520dw Firmware | All versions |
| Brother | Dcp-B7530dn Firmware | All versions |
| Brother | Dcp-B7535dw Firmware | All versions |
| Brother | Dcp-J1100dw Firmware | All versions |
| Brother | Dcp-J572dw Firmware | All versions |
| Brother | Dcp-J572n Firmware | All versions |
| Brother | Dcp-J577n Firmware | All versions |
| Brother | Dcp-J582n Firmware | All versions |
| Brother | Dcp-J772dw Firmware | All versions |
| Brother | Dcp-J774dw Firmware | All versions |
| Brother | Dcp-J972n Firmware | All versions |
| Brother | Dcp-J973n-B Firmware | All versions |
| Brother | Dcp-J973n-W Firmware | All versions |
| Brother | Dcp-J978n-B Firmware | All versions |
| Brother | Dcp-J978n-W Firmware | All versions |
| Brother | Dcp-J981n Firmware | All versions |
| Brother | Dcp-J982n-B Firmware | All versions |
| Brother | Dcp-J982n-W Firmware | All versions |
| Brother | Dcp-J988n\(Jpn\) Firmware | All versions |
| Brother | Dcp-L2520dw Firmware | All versions |
| Brother | Dcp-L2520dwr Firmware | All versions |
| Brother | Dcp-L2530dw Firmware | All versions |
| Brother | Dcp-L2531dw Firmware | All versions |
| Brother | Dcp-L2532dw Firmware | All versions |
| Brother | Dcp-L2535dw Firmware | All versions |
| Brother | Dcp-L2537dw Firmware | All versions |
| Brother | Dcp-L2540dn Firmware | All versions |
| Brother | Dcp-L2540dnr Firmware | All versions |
Showing 50 of 300 affected configurations. See NVD for the full list.
References
- https://global.brotherVendor Advisory
- https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-brother-printers/Exploit, Third Party Advisory
- https://global.brotherVendor Advisory
- https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-brother-printers/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13192?
How severe is CVE-2019-13192?
How do I fix CVE-2019-13192?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13187The Rich Text Formatter (Redactor) extension through v1.1.1 …
- CVE-2019-13188In Knowage through 6.1.1, an unauthenticated user can bypass…
- CVE-2019-13189In Knowage through 6.1.1, there is XSS via the start_url or …
- CVE-2019-1319An elevation of privilege vulnerability exists in Windows Er…7.8
- CVE-2019-13190In Knowage through 6.1.1, the sign up page does not invalida…
- CVE-2019-13191A SQL injection vulnerability in IntraMaps MapControl 8 allo…
- CVE-2019-13193Some Brother printers (such as the HL-L8360CDW v1.20) were a…8.8
- CVE-2019-13194Some Brother printers (such as the HL-L8360CDW v1.20) were a…7.5
- CVE-2019-13195The web application of some Kyocera printers (such as the EC…7.5
- CVE-2019-13196Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…8.8
- CVE-2019-13197Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…9.8
- CVE-2019-13198The web application of several Kyocera printers (such as the…6.1
Are you affected by CVE-2019-13192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
