vendor:
WorkCentre
by:
Juho Ranta, Henri Lindberg, CISA
3,3
CVSS
LOW
Denial of Service
N/A
CWE
Product Name: WorkCentre
Affected Version From: Controller+PS ROM Version 1.202.1 and 1.202.5
Affected Version To: Controller+PS ROM Version 1.202.1 and 1.202.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Xerox WorkCentre multiple models Denial of Service
During a brief assessment performed for Xerox WorkCentre 7132 it was discovered that LPD daemon implementation contains a weakness related to robustness of LPD protocol handling. Attacker can crash the whole device with a relatively simple attack. Recovering from the denial-of-service condition requires power cycling the device.
Mitigation:
Patch available for WC7232/7242