vendor:
WorkCentre 4150
by:
Francis Provencher
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: WorkCentre 4150
Affected Version From: Xerox WorkCentre 4150
Affected Version To: Xerox WorkCentre 4150
Patch Exists: YES
Related CWE: N/A
CPE: h:xerox:workcentre_4150
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Xerox Workcenter 4150 Remote Buffer Overflow
During a brief assessment performed on a Xerox WorkCentre 4150 it was discovered that PJL daemon implementation contains a weakness related to robustness of PJL protocol handling. Attacker can crash the service with a relatively simple attack. Recovering from the denial-of-service condition requires power cycling the device. Due to the black box nature of this Proof of concept attack, we are unable to know if remote code execution is possible.
Mitigation:
Power cycling the device to recover from the denial-of-service condition.