Lucene search

K
cve[email protected]CVE-2006-2113
HistoryAug 25, 2006 - 1:04 a.m.

CVE-2006-2113

2006-08-2501:04:00
CWE-287
web.nvd.nist.gov
29
fuji xerox
fxps
printing systems
http server
remote attackers
system configuration
denial of service

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.074 Low

EPSS

Percentile

94.1%

The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote attackers to modify system configuration via crafted requests, including changing the administrator password or causing a denial of service to the print server.

Affected configurations

NVD
Node
dell3000cn
OR
dell3010cn
OR
dell3100cn
OR
dell3110cn
OR
dell5100cn
OR
dell5110cn
OR
fuji_xeroxdocuprint_181
OR
fuji_xeroxdocuprint_181_network_option_card
OR
fuji_xeroxdocuprint_211
OR
fuji_xeroxdocuprint_211_network_option_card
OR
fuji_xeroxdocuprint_c1616
OR
fuji_xeroxdocuprint_c1616_network_option_card
OR
fuji_xeroxdocuprint_c2535a
OR
fuji_xeroxdocuprint_c525a
OR
fuji_xeroxdocuprint_c525a_network_option_card
OR
fuji_xeroxdocuprint_c830
OR
fuji_xeroxdocuprint_c830_network_option_card
OR
fuji_xeroxfuji_xerox_printing_systems_print_engine
OR
fuji_xeroxphaser_6201j

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.074 Low

EPSS

Percentile

94.1%