Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/121553/Brother-MFC-9970CDW-Firmware-0D-Cross-Site-Scripting.html | exploit vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84094 | vdb entry third party advisory |