CVE-2006-2112
Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT arguments to connect to systems for which access would be otherwise restricted.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.17% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dell/3000cn · dell/3010cn · dell/3100cn · dell/3110cn · dell/5100cn · dell/5110cn · fuji xerox/docuprint 181 · fuji xerox/docuprint 181 network option card · fuji xerox/docuprint 211 · fuji xerox/docuprint 211 network option card · fuji xerox/docuprint c1616 · fuji xerox/docuprint c1616 network option card · fuji xerox/docuprint c2535a · fuji xerox/docuprint c525a · fuji xerox/docuprint c525a network option card · fuji xerox/docuprint c830 · fuji xerox/docuprint c830 network option card · fuji xerox/fuji xerox printing systems print engine · fuji xerox/phaser 6201j
- Source
- cve@mitre.org
References
- http://itso.iu.edu/20060824_FXPS_Print_Engine_VulnerabilitiesPatch
- http://marc.info/?l=bugtraq&m=115652437223454&w=2
- http://secunia.com/advisories/21630Vendor Advisory
- http://secunia.com/advisories/22463Vendor Advisory
- http://www.osvdb.org/28249
- http://www.securityfocus.com/archive/1/444321/100/0/threaded
- http://www.securityfocus.com/bid/19711
- http://www.vupen.com/english/advisories/2006/3401Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28637
- http://itso.iu.edu/20060824_FXPS_Print_Engine_VulnerabilitiesPatch
- http://marc.info/?l=bugtraq&m=115652437223454&w=2
- http://secunia.com/advisories/21630Vendor Advisory
- http://secunia.com/advisories/22463Vendor Advisory
- http://www.osvdb.org/28249
- http://www.securityfocus.com/archive/1/444321/100/0/threaded
- http://www.securityfocus.com/bid/19711
- http://www.vupen.com/english/advisories/2006/3401Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28637
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.