PT-2018-13178 · Dell · Dell 2335Dn
Published
2018-08-23
·
Updated
2019-10-03
·
CVE-2018-15748
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell 2335dn printer with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010
Description
The admin interface of the affected printer allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the "Email Settings" webpage. In some cases, authentication can be achieved with the blank default password for the admin account.
Recommendations
For Dell 2335dn printers with the specified firmware versions, consider changing the default admin password to a strong password to prevent unauthorized access. As a temporary workaround, restrict access to the admin interface to minimize the risk of exploitation. Avoid using the default blank password for the admin account.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell 2335Dn