XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
BID:12785
Info
XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
| Bugtraq ID: | 12785 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2004 12:00AM |
| Updated: | Aug 30 2004 12:00AM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
Xerox WorkCentre Pro 55 Xerox WorkCentre Pro 45 Xerox WorkCentre Pro 40 Color Xerox WorkCentre Pro 35 Xerox WorkCentre Pro 32 Color Xerox WorkCentre M55 Xerox WorkCentre M45 Xerox WorkCentre M35 |
| Not Vulnerable: | |
Discussion
XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
WorkCentre is reported prone to an information disclosure vulnerability. This issue may allow an attacker to gain access to confidential print data.
It is reported that this issue arises in the ESS/Network Controller code. Reportedly, an attacker can cause the Immediate Image Overwrite security feature to fail, allowing confidential print data to be retrieved at a later time. The issue is reported to occur as the result of an unexpected power loss.
It is conjectured that this vulnerability is remote in nature and allows an attacker to access print data through the Web interface of the printer. The attacker may be able to access the print queue through the Web interface followed by printing potentially sensitive documents.
WorkCentre + PS M35/M45/M55, WorkCentre Pro 35/45/55 versions 1.01.108.1 to 1.02.370.1, and WorkCentre 32/40 Color versions 01.00.060 to 01.02.070.1 are affected.
WorkCentre is reported prone to an information disclosure vulnerability. This issue may allow an attacker to gain access to confidential print data.
It is reported that this issue arises in the ESS/Network Controller code. Reportedly, an attacker can cause the Immediate Image Overwrite security feature to fail, allowing confidential print data to be retrieved at a later time. The issue is reported to occur as the result of an unexpected power loss.
It is conjectured that this vulnerability is remote in nature and allows an attacker to access print data through the Web interface of the printer. The attacker may be able to access the print queue through the Web interface followed by printing potentially sensitive documents.
WorkCentre + PS M35/M45/M55, WorkCentre Pro 35/45/55 versions 1.01.108.1 to 1.02.370.1, and WorkCentre 32/40 Color versions 01.00.060 to 01.02.070.1 are affected.
Exploit / POC
XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
Solution:
The vendor has released a patch to address this issue.
Xerox WorkCentre Pro 32 Color
Xerox WorkCentre M35
Xerox WorkCentre M55
Xerox WorkCentre Pro 55
Xerox WorkCentre Pro 40 Color
Xerox WorkCentre M45
Xerox WorkCentre Pro 35
Xerox WorkCentre Pro 45
Solution:
The vendor has released a patch to address this issue.
Xerox WorkCentre Pro 32 Color
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre M35
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre M55
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre Pro 55
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre Pro 40 Color
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre M45
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre Pro 35
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
Xerox WorkCentre Pro 45
-
XEROX cert_XRX04B_patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_XRX04B_patch.zip
References
XEROX WorkCentre ESS/Network Controller Print Data Information Disclosure Vulnerability
References:
References:
- Xerox Homepage (Xerox)
- XEROX SECURITY BULLETIN XRX04- 006 (XEROX)