Security researchers found two flaws affecting Xerox Versalink MFP printers
The flaws could be used in “pass-back” attacks to steal login credentials
Patches and workarounds are already available, so update now
Some Xerox printers are vulnerable to a “pass-back” attack which can be used to steal login credentials, experts have warned.
Cybersecurity researchers Rapid7 discovered the vulnerability and reported it in an in-depth analysis, saying that during security testing, it found a vulnerability affecting Xerox Versalink MFP printers. This flaw can be abused either via LDAP, or SMB/FTP, to mount a pass-back attack, and with that in mind, it was given two CVEs: CVE-2024-12510 for LDAP, and CVE-2024-12511 for SMB/FTP. The vulnerabilities were given severity scores of 6.7/10 (medium) and 7.6/10 (high) respectively, and affect firmware versions 57.69.91 and earlier.
+ There are no comments
Add yours