CVE-2008-0374

OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:oki:c5510mfp_firmware:1.01:*:*:*:*:*:*:*
cpe:2.3:h:oki:c5510mfp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 00:41

Type Values Removed Values Added
References () http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory () http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory
References () http://securityreason.com/securityalert/3569 - Third Party Advisory () http://securityreason.com/securityalert/3569 - Third Party Advisory
References () http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link () http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link
References () http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry

25 Jan 2024, 20:41

Type Values Removed Values Added
First Time Oki
Oki c5510mfp
Oki c5510mfp Firmware
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 7.5
CWE CWE-310 CWE-319
CPE cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:pu_01.03.01:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:web_page_1.00:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:system_fw_1.01:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:cu_h2.15:*:*:*:*:*:*:*
cpe:2.3:h:oki:c5510mfp:-:*:*:*:*:*:*:*
cpe:2.3:o:oki:c5510mfp_firmware:1.01:*:*:*:*:*:*:*
References (MISC) http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - (MISC) http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry
References (BUGTRAQ) http://www.securityfocus.com/archive/1/486511/100/0/threaded - (BUGTRAQ) http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/27339 - (BID) http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry
References (SREASON) http://securityreason.com/securityalert/3569 - (SREASON) http://securityreason.com/securityalert/3569 - Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/28553 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory

Information

Published : 2008-01-22 20:00

Updated : 2024-11-21 00:41


NVD link : CVE-2008-0374

Mitre link : CVE-2008-0374

CVE.ORG link : CVE-2008-0374


JSON object : View

Products Affected

oki

  • c5510mfp
  • c5510mfp_firmware
CWE
CWE-319

Cleartext Transmission of Sensitive Information