PT-2023-19066 · Cl4Nx · Cl4Nx
CVE-2023-23594
·
Publicado
2023-03-31
·
Atualizado
2025-02-18
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CL4NX printer versions prior to 1.13.3-u724 r2
Description
An authentication bypass issue in the web client interface of the CL4NX printer allows remote unauthenticated attackers to execute commands intended for valid and authenticated users. This includes actions such as file uploads and configuration changes.
Recommendations
For versions prior to 1.13.3-u724 r2, update the firmware to version 1.13.3-u724 r2 or later to resolve the issue. As a temporary workaround, consider restricting access to the web client interface until the update can be applied.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cl4Nx