CVE-2008-0374
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- oki/c5510mfp firmware
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28553Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/3569Third Party Advisory
- http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.htmlBroken Link
- http://www.securityfocus.com/archive/1/486511/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27339Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39775VDB Entry
- http://secunia.com/advisories/28553Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/3569Third Party Advisory
- http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.htmlBroken Link
- http://www.securityfocus.com/archive/1/486511/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27339Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39775VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.