PT-2019-12103 · Zebra · Zebra Industrial Printers
Publicado
2019-08-20
·
Atualizado
2020-10-02
·
CVE-2019-10960
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zebra Industrial Printers All Versions
Description
The issue concerns Zebra printers being shipped with unrestricted end-user access to front panel options. If a passcode is set to limit front panel functionality, an attacker can send specially crafted packets over the network to a port on the printer, and the printer will respond with an array of information that includes the front panel passcode. To exploit this, an attacker must have physical access to the front panel to enter the passcode and access full functionality.
Recommendations
For Zebra Industrial Printers All Versions, consider restricting physical access to the front panel to minimize the risk of exploitation. As a temporary workaround, avoid using the passcode limitation option for the front panel until a more secure solution is available.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zebra Industrial Printers