CVE-2018-15748
Summary
| CVE | CVE-2018-15748 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-23 15:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configured SMTP or LDAP password by viewing the HTML source code of the Email Settings webpage. In some cases, authentication can be achieved with the blank default password for the admin account. NOTE: the vendor indicates that this is an "End Of Support Life" product. |
Risk And Classification
Problem Types: CWE-521
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | 2335dn | - | All | All | All |
| Hardware | Dell | 2335dn | - | All | All | All |
| Operating System | Dell | 2335dn Engine Firmware | 1.10.65 | All | All | All |
| Operating System | Dell | 2335dn Engine Firmware | 1.10.65 | All | All | All |
| Operating System | Dell | 2335dn Network Firmware | v4.02.15(2335dn_mfp)_11-22-2010 | All | All | All |
| Operating System | Dell | 2335dn Network Firmware | v4.02.15\(2335dn_mfp\)_11-22-2010 | All | All | All |
| Operating System | Dell | 2335dn Network Firmware | v4.02.15\(2335dn_mfp\)_11-22-2010 | All | All | All |
| Operating System | Dell | 2335dn Printer Firmware | 2.70.05.02 | All | All | All |
| Operating System | Dell | 2335dn Printer Firmware | 2.70.05.02 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dell 2335dn Password Disclosure – Gerren Murphy | MISC | www.gerrenmurphy.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.