Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10960

Опубликовано: 20 авг. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zebra:zt610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt610:*:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:zebra:zt620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt620:*:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:zebra:zt510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt510:*:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:zebra:zt410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt410:*:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:zebra:zt420_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt420:*:*:*:*:*:*:*:*
Конфигурация 6

Одновременно

cpe:2.3:o:zebra:zt220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt220:*:*:*:*:*:*:*:*
Конфигурация 7

Одновременно

cpe:2.3:o:zebra:zt230_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt230:*:*:*:*:*:*:*:*
Конфигурация 8

Одновременно

cpe:2.3:o:zebra:220xi4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zebra:220xi4:*:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-522
CWE-522

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

EPSS

Процентиль: 38%
0.00163
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-522
CWE-522