Unix Printing Vulnerabilities Enable Easy DDoS Attacks
ID: e23567d1-0566-51c8-aa0c-7390dc061897
STIX ID: report--e23567d1-0566-51c8-aa0c-7390dc061897
Feed Name: Dark Reading
Researchers disclosed four CUPS vulnerabilities (CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177) that enable remote code execution and an easy amplification DDoS technique: a single crafted UDP packet to a vulnerable CUPS server can trigger a much larger, partially attacker-controlled IPP/HTTP request toward a target. Akamai found ~198,000 Internet-accessible CUPS hosts, of which ~58,000 are vulnerable to the DDoS corralling, potentially enabling low-cost, high-connection-volume attacks; recommended mitigations include patching, removing CUPS if unnecessary, and blocking UDP/631 to the public Internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
