Why do Most Organizations Fail at Cyber Security?
August 20, 2019
Rewterz
Rewterz Threat Advisory – Sierra Wireless AirLink ALEOS Multiple Vulnerabilities
August 21, 2019

Rewterz Threat Advisory – CVE-2019-10960 – Zebra Industrial Printers Unprotected Credentials Vulnerability

Severity

Medium

Analysis Summary

Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

Impact

Insufficiently protected credentials

Affected Vendors

Zebra

Affected Products

Industrial Printers

Remediation

Zebra has released a new version of the software that can be obtained at: https://www.zebra.com/linkos