Tektronix PhaserLink Webserver Vulnerability

BID:806

Info

Tektronix PhaserLink Webserver Vulnerability

Bugtraq ID: 806
Class: Access Validation Error
CVE: CVE-1999-1508
Remote: Yes
Local: No
Published: Nov 17 1999 12:00AM
Updated: Jul 11 2009 12:56AM
Credit: This bug was discovered and posted to the Bugtraq mailing list by Dennis W. Mattison <[email protected]> on Tue, 16 Nov 1999.
Vulnerable: Tektronix Phaser Network Printer 930
Tektronix Phaser Network Printer 840
Tektronix Phaser Network Printer 750DP
Tektronix Phaser Network Printer 750
Tektronix Phaser Network Printer 740
Not Vulnerable:

Discussion

Tektronix PhaserLink Webserver Vulnerability

Certain versions of the Tektronix PhaserLink printer ship with a webserver designed to help facilitate configuration of the device. This service is essentially administrator level access as it can completely modify the system characteristics, restart the machine, asign services etc.

In at least one version of this printer there are a series of undocumented URL's which will allow remote users to retrieve the administrator password. Once the password is obtained by the user, they can manipulate the printer in any way they see fit.

Solution / Fix

Tektronix PhaserLink Webserver Vulnerability

Solution:
1. Block Port 80 access to this printer via a router or firewall. This will prevent access to this software from those outside the network. Also, since very rarely will anyone print from outside the local network, setting the default gateway be the same as the IP address will keep outside users from exploiting this service.

2. Disable the PhaserLink Webserver on the printer. This can be accomplished through the control panel, switching the HTTP Protocol to Disabled (Under Printer Configuration | Network Settings | HTTP), but it can also be accomplished via the URL http://printername/ncl_items?SUBJECT=2097, then switch the setting "On" to off.

References

Tektronix PhaserLink Webserver Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report