5.3

CVE-2024-47176

Exploit

cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can cause the `Get-Printer-Attributes` IPP request to an attacker controlled URL. When combined with other vulnerabilities, such as CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, an attacker can execute arbitrary commands remotely on the target machine without authentication when a malicious printer is printed to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openprinting ≫ Cups-browsed Version 2.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 50.61% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-1327 Binding to an Unrestricted IP Address

The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.

https://github.com/OpenPrinting/cups-browsed/security/advisories/GHSA-rj88-6mr5-rcw8
Vendor Advisory
Exploit
https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-p9rh-jxmq-gq47
Not Applicable
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5
Not Applicable
https://github.com/OpenPrinting/libppd/security/advisories/GHSA-7xfx-47qg-grp6
Not Applicable
https://www.cups.org
Product
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I
Third Party Advisory
Exploit
https://github.com/OpenPrinting/cups-browsed/blob/master/daemon/cups-browsed.c#L13992
Product
http://www.openwall.com/lists/oss-security/2024/09/27/6
Mailing List
https://github.com/OpenPrinting/cups-browsed/commit/1debe6b140c37e0aa928559add4abcc95ce54aa2
Patch
https://lists.debian.org/debian-lts-announce/2024/09/msg00048.html
https://security.netapp.com/advisory/ntap-20241011-0001/
http://www.openwall.com/lists/oss-security/2025/09/11/2