CVE-2019-10960
Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- zebra/zt610 firmware · zebra/zt620 firmware · zebra/zt510 firmware · zebra/zt410 firmware · zebra/zt420 firmware · zebra/zt220 firmware · zebra/zt230 firmware · zebra/220xi4 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/icsa-19-232-01Mitigation, Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-19-232-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.