Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address
Published Feb 21, 2020
8.8
HIGHCVSS 3.1
EPSS 1.07%
Description
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.
Affected products
No data.
Configuration 1
- < 073.060.000.02300
Running on/with
- n/a
Configuration 2
- < 073.060.000.02300
Running on/with
- n/a
Configuration 3
- < 073.190.000.02300
Running on/with
- n/a
Configuration 4
- < 073.190.000.02300
Running on/with
- n/a
Configuration 5
- < 073.091.000.02300
Running on/with
- n/a
Configuration 6
- < 073.091.000.02300
Running on/with
- n/a
Configuration 7
- < 073.110.000.02300
Running on/with
- n/a
Configuration 8
- < 073.110.000.02300
Running on/with
- n/a
Configuration 9
- < 073.030.000.02300
Running on/with
- n/a
Configuration 10
- < 073.030.000.02300
Running on/with
- n/a
Configuration 11
- < 073.010.000.02300
Running on/with
- n/a
Configuration 12
- < 073.010.000.02300
Running on/with
- n/a
Configuration 13
- < 073.010.000.02300
Running on/with
- n/a
Configuration 14
- < 073.010.000.02300
Running on/with
- n/a
Configuration 15
- < 073.200.000.02300
Running on/with
- n/a
Configuration 16
- < 073.200.000.02300
Running on/with
- n/a
Configuration 17
- < 073.050.000.02300
Running on/with
- n/a
Configuration 18
- < 073.020.000.02300
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30151 Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2020/02/cert_Security_Mini_Bulletin_XRX20D_for_ConnectKey.pdf x_refsource_MISCPatchVendor Advisory
- https://www.securicon.com/hackers-can-gain-active-directory-privileges-through-new-vulnerability-in-xerox-printers/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30151 | Advisory | |
| https://securitydocs.business.xerox.com/wp-content/uploads/2020/02/cert_Security_Mini_Bulletin_XRX20D_for_ConnectKey.pdf | x_refsource_MISCPatchVendor Advisory | |
| https://www.securicon.com/hackers-can-gain-active-directory-privileges-through-new-vulnerability-in-xerox-printers/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data