← back
CVE-2017-16249

CVE-2017-16249

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 59%
from disclosure to weapon0 days
Published on NVDNov 9
1st PoCNov 2
metasploitNov 2
exploitation probability
59%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.