← Back

Phaser 3320 Firmware

phaser_3320_firmware

Vendor: Xerox • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register parameters, because the size used within a memcpy() function, which copied the action value into a local variable, was not checked properly.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the a...Show more
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Se...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.Show less