Skip to main content

Samsung Printer firmware contains a backdoor administrator account vulnerability

Last Update Date: 27 Nov 2012 10:58 Release Date: 27 Nov 2012 4109 Views

RISK: High Risk

TYPE: Operating Systems - Others OS

TYPE: Others OS

A vulnerability has been identified on Samsung Printer firmware, which can be exploited by remote attacker to take control of an affected device.

 

Samsung printers (as well as some Dell printers manufactured by Samsung) contain a hardcoded SNMP full read-write community string that remains active even when SNMP is disabled in the printer management utility.

 

Note:

No patch is currently avaliable for this vulnerbility


Impact

  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Printers with Samsung firmware released prior October 31, 2012

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • No patch is currently avaliable for this vulnerbility
  • Workaround:
    only allow connections from trusted hosts and networks

Vulnerability Identifier


Source


Related Link