CVE-2024-47176

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Nov 21, 2024
CWE ID 1327

Summary

CVE-2024-47176 is a vulnerability affecting the `cups-browsed` component of the Common Unix Printing System (CUPS). This open-source printing system is known to bind to `INADDR_ANY:631`, making `cups-browsed` trust packets from any source. An attacker can exploit this trust vulnerability by manipulating the `Get-Printer-Attributes` IPP request, leading to potential remote code execution when a malicious printer is printed to. This vulnerability can be particularly dangerous when combined with other CUPS vulnerabilities like CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177, enabling unauthenticated attackers to execute arbitrary commands on the target machine.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share