vendor:
DocuCentre-V 3065 Printer
by:
vr_system
7.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: DocuCentre-V 3065 Printer
Affected Version From: DocuCentre-IV,DocuCentre-VI,DocuCentre-V,ApeosPort-VI,ApeosPort-V
Affected Version To: DocuCentre-V 3065,ApeosPort-VI C3371,ApeosPort-V C4475,ApeosPort-V C3375,DocuCentre-VI C2271,ApeosPort-V C5576,DocuCentre-IV C2263,DocuCentre-V C2263,ApeosPort-V 5070
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: DocuCentre-V 3065,ApeosPort-VI C3371,ApeosPort-V C4475,ApeosPort-V C3375,DocuCentre-VI C2271,ApeosPort-V C5576,DocuCentre-IV C2263,DocuCentre-V C2263,ApeosPort-V 5070
2018
FUJI XEROX DocuCentre-V 3065 Printer – Remote Command Execution
A vulnerability in FUJI XEROX DocuCentre-V 3065 Printer allows an attacker to write files to the printer. This is achieved by bypassing the pin and setting the CPLOCK and DISKLOCK to OFF. The attacker can then use the FSDOWNLOAD and FSUPLOAD commands to write files to the printer.
Mitigation:
Ensure that the printer is updated to the latest version and that the CPLOCK and DISKLOCK settings are enabled.