PT-2018-13178 · Dell · Dell 2335Dn

Published

2018-08-23

·

Updated

2019-10-03

·

CVE-2018-15748

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell 2335dn printer with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010
Description The admin interface of the affected printer allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the "Email Settings" webpage. In some cases, authentication can be achieved with the blank default password for the admin account.
Recommendations For Dell 2335dn printers with the specified firmware versions, consider changing the default admin password to a strong password to prevent unauthorized access. As a temporary workaround, restrict access to the admin interface to minimize the risk of exploitation. Avoid using the default blank password for the admin account.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15748

Affected Products

Dell 2335Dn