← Back

CVE-2020-9330

nvd nist
Published: Feb 21, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.

Affected (18)

18 products
Workcentre 3655 Firmware
Workcentre 3655i Firmware
Workcentre 5845 Firmware
Workcentre 5855 Firmware
Workcentre 5945 Firmware
Workcentre 5955 Firmware
Workcentre 6655 Firmware
Workcentre 6655i Firmware
Workcentre 7220 Firmware
Workcentre 7225 Firmware
Workcentre 7830 Firmware
Workcentre 7835 Firmware
Workcentre 7845 Firmware
Workcentre 7855 Firmware
Workcentre 7970 Firmware
Workcentre 7970i Firmware
Workcentre Ec7836 Firmware
Workcentre Ec7856 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.060.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 3655
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.060.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 3655i
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.190.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 5845
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.190.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 5855
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.091.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 5945
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.091.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 5955
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.110.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 6655
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.110.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 6655i
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.030.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7220
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.030.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7225
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.010.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7830
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.010.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7835
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.010.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7845
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.010.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7855
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.200.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7970
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.200.000.02300
Running on/withPlatform Versions
Xerox
Workcentre 7970i
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.050.000.02300
Running on/withPlatform Versions
Xerox
Workcentre Ec7836
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 073.020.000.02300
Running on/withPlatform Versions
Xerox
Workcentre Ec7856
All versions

Timeline

No history available yet.