Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4957

Опубликовано: 11 окт. 2023
Источник: nvd
CVSS3: 5.4
CVSS3: 4.3
EPSS Низкий

Описание

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zebra:zt410_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:zebra:zt410:-:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00007
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 5.4
github
больше 2 лет назад

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

EPSS

Процентиль: 0%
0.00007
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-288