Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.

Project Subscriptions

Vendors Products
Workcentre 3655 Subscribe
Workcentre 3655 Firmware Subscribe
Workcentre 3655i Subscribe
Workcentre 3655i Firmware Subscribe
Workcentre 5845 Subscribe
Workcentre 5845 Firmware Subscribe
Workcentre 5855 Subscribe
Workcentre 5855 Firmware Subscribe
Workcentre 5945 Subscribe
Workcentre 5945 Firmware Subscribe
Workcentre 5955 Subscribe
Workcentre 5955 Firmware Subscribe
Workcentre 6655 Subscribe
Workcentre 6655 Firmware Subscribe
Workcentre 6655i Subscribe
Workcentre 6655i Firmware Subscribe
Workcentre 7220 Subscribe
Workcentre 7220 Firmware Subscribe
Workcentre 7225 Subscribe
Workcentre 7225 Firmware Subscribe
Workcentre 7830 Subscribe
Workcentre 7830 Firmware Subscribe
Workcentre 7835 Subscribe
Workcentre 7835 Firmware Subscribe
Workcentre 7845 Subscribe
Workcentre 7845 Firmware Subscribe
Workcentre 7855 Subscribe
Workcentre 7855 Firmware Subscribe
Workcentre 7970 Subscribe
Workcentre 7970 Firmware Subscribe
Workcentre 7970i Subscribe
Workcentre 7970i Firmware Subscribe
Workcentre Ec7836 Subscribe
Workcentre Ec7836 Firmware Subscribe
Workcentre Ec7856 Subscribe
Workcentre Ec7856 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-30151 Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:26:16.065Z

Reserved: 2020-02-21T00:00:00

Link: CVE-2020-9330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-21T23:15:11.497

Modified: 2024-11-21T05:40:25.413

Link: CVE-2020-9330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses