PT-2024-2633 · Unknown · Myq Print Server
Dylan Wesselink
+1
·
Published
2024-01-23
·
Updated
2024-02-22
·
CVE-2024-22076
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyQ Print Server versions prior to 8.2 patch 43
Description
The issue is related to the administrative interface of the MyQ Print Server, where remote authenticated administrators can execute arbitrary code via PHP scripts. This is due to weaknesses in the authentication procedure, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations
For MyQ Print Server versions prior to 8.2 patch 43, update to version 8.2 patch 43 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrative interface and PHP scripts to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myq Print Server