CVE-2023-28369
Last modified
CVE-2023-28369 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Brother iPrint&Scan V6.11.2 and earlier contains an improper access control vulnerability. This vulnerability may be exploited by the other app installed on the victim user's Android device, which may lead to displaying the settings and/or log information of the affected app as a print preview.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Brother iPrint&Scan V6.11.2 and earlier contains an improper access control vulnerability. This vulnerability may be exploited by the other app installed on the victim user's Android device, which may lead to displaying the settings and/or log information of the affected app as a print preview.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Brother | Iprint\&Scan | < 6.11.3 |
References
- https://faq.brother.co.jp/app/answers/detail/a_id/13468Vendor Advisory
- https://jvn.jp/en/vu/JVNVU97891206/Third Party Advisory
- https://faq.brother.co.jp/app/answers/detail/a_id/13468Vendor Advisory
- https://jvn.jp/en/vu/JVNVU97891206/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-28369?
How severe is CVE-2023-28369?
How do I fix CVE-2023-28369?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-28362The redirect_to method in Rails allows provided values to co…4
- CVE-2023-28364An Open Redirect vulnerability exists prior to version 1.52.…6.1
- CVE-2023-28365A backup file vulnerability found in UniFi applications (Ver…9.1
- CVE-2023-28366The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0…7.5
- CVE-2023-28367Cross-site scripting vulnerability in CTA post function of V…5.4
- CVE-2023-28368TP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2…5.7
- CVE-2023-2837Stack-based Buffer Overflow in GitHub repository gpac/gpac p…5.5
- CVE-2023-28370Open redirect vulnerability in Tornado versions 6.3.1 and ea…6.1
- CVE-2023-28371In Stellarium through 1.2, attackers can write to files that…9.8
- CVE-2023-28372A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereb…2.7
- CVE-2023-28373A flaw exists in FlashArray Purity whereby an array administ…2.7
- CVE-2023-28374Improper input validation for some Intel(R) PROSet/Wireless …6.5
Are you affected by CVE-2023-28369?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
