OSVDB ID: 28250

Title: Fuji Xerox Printing Systems (FXPS) Print Engine Crafted Request HTTP Authentication Bypass

Info

Disclosure

Aug 24, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Fuji Xerox Printing Systems (FXPS) Print Engine contains a flaw that may allow bypassing certain security restrictions. The issue is triggered because the embedded HTTP server does not authenticate certain HTTP requests correctly. It is possible that the flaw may allow a malicious user to make unauthorized changes to the system configuration or to cause a denial of service resulting in a loss of integrity or availability.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Integrity, Loss of Availability
Exploit: Exploit Unknown

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Dell has released a patch to address this vulnerability.

Products

Dell

Printer

5110cn
3110cn
3010cn
5100cn
3100cn
3000cn

References

Credit

  • Sean Krulewitch - Indiana University


Direct URL: http://osvdb.org/28250