Skip to content
  • There are no suggestions because the search field is empty.

NetWitness Platform: OpenPrinting CUPS vulnerabilities

Tags: Advisories, Security Advisories

Advisory Type

Security


Advisory Content

This advisory addresses the recent vulnerabilities identified in various components of the CUPS printing system. The specific vulnerabilities are CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177. These vulnerabilities could potentially allow remote code execution through malicious IPP services and improperly sanitized IPP attributes.


CVE Identifier


CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177


Severity

Summary and Impact Analysis for NetWitness


NetWitness utilizes the cups-libs library, which is not directly impacted by the aforementioned vulnerabilities. The vulnerabilities are specific to other components of the CUPS system, such as libcupsfilters, libppd, cups-browsed, and cups-filters. As Netwitness does not include these components, it is not vulnerable to these specific CVEs.


Potential for Exploitation


The vulnerabilities (CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177) can be exploited through a specific chain of events. However, NetWitness is not vulnerable to these vulnerabilities due to the absence of the cups-browsed service. For exploitation to occur, the following conditions must be met:


1. The cups-browsed service must be enabled or started.
2. An attacker must gain access to a vulnerable server, which:

  1. Allows unrestricted access, such as from the public internet, or
  2. Gains access to an internal network where local connections are trusted.

3. The attacker advertises a malicious IPP server, thereby provisioning a malicious printer.
4. A potential victim attempts to print using the malicious device.
5. This attempted printing allows the attacker to execute arbitrary code on the victim’s machine.


Since NetWitness only uses cups-libs and does not incorporate the cups-browsed service or other affected components, these conditions cannot be met. Therefore, there is no potential for exploitation of these vulnerabilities within our product.


Level of Risk Incurred and Introduced


There is no risk incurred by Netwitness from the vulnerabilities CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177, as it does not use the affected components.


Affected Versions


Not Applicable: Netwitness is not affected by CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177.


Mitigation Steps


No action is required for users of NetWitness regarding these specific vulnerabilities. We recommend keeping all software up to date and following general security best practices to ensure the safety and integrity of your systems.


EOPS Policy


NetWitness has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.


Legal Information


Read and use the information in this NetWitness Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact RSA Customer Support. RSA Security LLC and its affiliates distribute NetWitness Security Advisories in order to bring to the attention of users of the affected RSA products, important security information.
NetWitness recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without a warranty of any kind. NetWitness disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement.
In no event shall RSA, its affiliates or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.