PT-2019-12103 · Zebra · Zebra Industrial Printers
Published
2019-08-20
·
Updated
2020-10-02
·
CVE-2019-10960
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zebra Industrial Printers All Versions
Description
The issue concerns Zebra printers being shipped with unrestricted end-user access to front panel options. If a passcode is set to limit front panel functionality, an attacker can send specially crafted packets over the network to a port on the printer, and the printer will respond with an array of information that includes the front panel passcode. To exploit this, an attacker must have physical access to the front panel to enter the passcode and access full functionality.
Recommendations
For Zebra Industrial Printers All Versions, consider restricting physical access to the front panel to minimize the risk of exploitation. As a temporary workaround, avoid using the passcode limitation option for the front panel until a more secure solution is available.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zebra Industrial Printers