CVE-2024-47176 is a medium-severity vulnerability affecting openprinting cups-browsed, where the service binds to INADDR_ANY:631, trusting all incoming packets and allowing it to be directed to an attacker-controlled URL for IPP requests. This flaw, when chained with other vulnerabilities, enables unauthenticated remote code execution on target machines when a malicious printer is used. The CVSS score is 5.3 (Medium), indicating a network-based attack with low complexity and no user interaction required, potentially leading to information disclosure. While not yet in the KEV catalog, exploit modules exist in Metasploit, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1CPE matchmatch criteria | cpe:2.3:a:openprinting:cups-browsed:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source
Sep 26, 2024