Overview
Certain Lexmark devices are vulnerable to unverified password changes and stored cross-site scripting attacks.
Description
CWE-620: Unverified Password Change - CVE-2013-6032 Certain models of Lexmark laser printers and MarkNet devices are vulnerable to an attack which allows a remote unauthenticated attacker to change the administrative password of the printer's web administration interface. The interface does not perform sufficient validation of the vac.255.GENPASSWORD parameter in POST requests to the /cgi-bin/postpf/cgi-bin/dynamic/config/config.html page, allowing an unauthenticated remote attacker to reset the administrative password to an empty string. |
Impact
An attacker may be able to run arbitrary script in the context of a victim's browser. The attacker may also be able to gain full administrative control of the printer. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Temporal | 7.4 | E:F/RL:OF/RC:C |
Environmental | 1.9 | CDP:N/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Jeff Popio for reporting this vulnerability.
This document was written by Todd Lewellen.
Other Information
CVE IDs: | CVE-2013-6032, CVE-2013-6033 |
Date Public: | 2014-01-31 |
Date First Published: | 2014-01-31 |
Date Last Updated: | 2014-01-31 15:34 UTC |
Document Revision: | 19 |