logo

Unix Printing Vulnerabilities Enable Easy DDoS Attacks

ID: e23567d1-0566-51c8-aa0c-7390dc061897

STIX ID: report--e23567d1-0566-51c8-aa0c-7390dc061897

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-10-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers disclosed four CUPS vulnerabilities (CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177) that enable remote code execution and an easy amplification DDoS technique: a single crafted UDP packet to a vulnerable CUPS server can trigger a much larger, partially attacker-controlled IPP/HTTP request toward a target. Akamai found ~198,000 Internet-accessible CUPS hosts, of which ~58,000 are vulnerable to the DDoS corralling, potentially enabling low-cost, high-connection-volume attacks; recommended mitigations include patching, removing CUPS if unnecessary, and blocking UDP/631 to the public Internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.