Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxgm-7qvp-hg2x

Опубликовано: 11 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

EPSS

Процентиль: 0%
0.00007
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

EPSS

Процентиль: 0%
0.00007
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288