vendor:
3121/3122 Printer
by:
Herman Groeneveld aka sh4d0wman
7,5
CVSS
HIGH
Denial of Service (DoS)
N/A
CWE
Product Name: 3121/3122 Printer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
OCE 3121/3122 Printer DoS Exploit
The printer runs a webserver to provide various printing tasks from java enabled browsers. Input is being filtered for bad characters. However, it is vulnerable to a long URL request. This will either reboot or crash the device. On crash, the 'system' LED on the printer changes from green to orange. No further printing is done until somebody resets the printer by flipping the power switch. E675 error is displayed in the printer display. On reboot, printing resumes after the device has completed its reboot cycle.
Mitigation:
Limit the length of the URL request.