0.2 C
United States of America
Wednesday, March 19, 2025

New Xerox Printer Flaws May Let Attackers Seize Home windows Lively Listing Credentials


Feb 18, 2025Ravie LakshmananVulnerability / Enterprise Safety

New Xerox Printer Flaws May Let Attackers Seize Home windows Lively Listing Credentials

Safety vulnerabilities have been disclosed in Xerox VersaLink C7025 Multifunction printers (MFPs) that might enable attackers to seize authentication credentials by way of pass-back assaults by way of Light-weight Listing Entry Protocol (LDAP) and SMB/FTP companies.

“This pass-back model assault leverages a vulnerability that permits a malicious actor to change the MFP’s configuration and trigger the MFP machine to ship authentication credentials again to the malicious actor,” Rapid7 safety researcher Deral Heiland mentioned.

“If a malicious actor can efficiently leverage these points, it might enable them to seize credentials for Home windows Lively Listing. This implies they might then transfer laterally inside a company’s setting and compromise different crucial Home windows servers and file techniques.”

Cybersecurity

The recognized vulnerabilities, which have an effect on firmware variations 57.69.91 and earlier, are listed beneath –

Profitable exploitation of CVE-2024-12510 might enable authentication info to be redirected to a rogue server, probably exposing credentials. This, nevertheless, requires an attacker to realize entry to the LDAP configuration web page and that LDAP is used for authentication.

CVE-2024-12511, likewise, permits a malicious actor to realize entry to the person handle e-book configuration to change the SMB or FTP server’s IP handle and make it level to a bunch underneath their management, inflicting SMB or FTP authentication credentials to be captured throughout file scan operations.

“For this assault to achieve success, the attacker requires an SMB or FTP scan operate to be configured inside the person’s handle e-book, in addition to bodily entry to the printer console or entry to remote-control console by way of the online interface,” Heiland famous. “This will require admin entry until person stage entry to the remote-control console has been enabled.”

Following accountable disclosure on March 26, 2024, the vulnerabilities have been addressed as a part of Service Pack 57.75.53 launched late final month for VersaLink C7020, 7025, and 7030 collection printers.

Cybersecurity

If instant patching will not be an possibility, customers are advisable to set a fancy password for the admin account, keep away from utilizing Home windows authentication accounts which have elevated privileges, and disable the remote-control console for unauthenticated customers.

The event comes as Specular founder and CEO Peyton Smith detailed an unauthenticated SQL injection vulnerability affecting a extensively deployed healthcare software program named HealthStream MSOW (CVE-2024-56735) that might result in a full database compromise, permitting menace actors to entry delicate information of 23 healthcare organizations from the general public web.

The corporate mentioned it recognized 50 situations of internet-exposed MSOW situations, of which 23 are prone to safety shortcomings.

The vulnerability might enable “all the database might be returned in-band, that means an attacker might retrieve the plaintext database contents in a HTTP response from a crafted SQL injection HTTP payload,” Smith mentioned.

Discovered this text attention-grabbing? Comply with us on Twitter and LinkedIn to learn extra unique content material we put up.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles