CVE-2017-9632

A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions. The username and password are transmitted insecurely.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-17-208-03 Mitigation Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-17-208-03 Mitigation Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_g5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_g5:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_g5_s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_g5_s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_m5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_m5:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_360_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_360:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_360_plus_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_360_plus:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_autoxpress_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_autoxpress:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:pdqinc:laserwash_autoxpress_plus_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserwash_autoxpress_plus:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:pdqinc:laserjet_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:laserjet:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:pdqinc:protouch_tandem_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:protouch_tandem:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:pdqinc:protouch_icon_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:protouch_icon:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:pdqinc:protouch_autogloss_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pdqinc:protouch_autogloss:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:36

Type Values Removed Values Added
References () https://ics-cert.us-cert.gov/advisories/ICSA-17-208-03 - Mitigation, Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-17-208-03 - Mitigation, Third Party Advisory, US Government Resource

Information

Published : 2017-08-07 08:29

Updated : 2024-11-21 03:36


NVD link : CVE-2017-9632

Mitre link : CVE-2017-9632

CVE.ORG link : CVE-2017-9632


JSON object : View

Products Affected

pdqinc

  • laserwash_m5
  • laserwash_360_firmware
  • laserwash_g5_s_firmware
  • protouch_icon
  • protouch_tandem
  • laserwash_autoxpress
  • protouch_icon_firmware
  • laserwash_360
  • laserjet
  • laserwash_g5
  • laserjet_firmware
  • laserwash_autoxpress_plus
  • protouch_autogloss
  • protouch_autogloss_firmware
  • laserwash_g5_s
  • laserwash_autoxpress_plus_firmware
  • protouch_tandem_firmware
  • laserwash_360_plus
  • laserwash_m5_firmware
  • laserwash_g5_firmware
  • laserwash_360_plus_firmware
  • laserwash_autoxpress_firmware
CWE
CWE-311

Missing Encryption of Sensitive Data