CVE-2017-13771
Summary
| CVE | CVE-2017-13771 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-07 13:29:00 UTC |
| Updated | 2021-07-20 17:15:00 UTC |
| Description | Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2) cgi-bin/direct/printer/prtappauth/apps/ImportExportServlet. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lexmark | Scan To Network | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Lexmark Security Advisories | MISC | support.lexmark.com | |
| Full Disclosure: Lexmark Scan to Network (SNF) printer application <= 3.2.9 Information Exposure | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Lexmark Scan To Network (SNF) 3.2.9 Information Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.