Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Xerox
Subscribe
|
Workcentre 3655
Subscribe
Workcentre 3655 Firmware
Subscribe
Workcentre 3655i
Subscribe
Workcentre 3655i Firmware
Subscribe
Workcentre 5845
Subscribe
Workcentre 5845 Firmware
Subscribe
Workcentre 5855
Subscribe
Workcentre 5855 Firmware
Subscribe
Workcentre 5945
Subscribe
Workcentre 5945 Firmware
Subscribe
Workcentre 5955
Subscribe
Workcentre 5955 Firmware
Subscribe
Workcentre 6655
Subscribe
Workcentre 6655 Firmware
Subscribe
Workcentre 6655i
Subscribe
Workcentre 6655i Firmware
Subscribe
Workcentre 7220
Subscribe
Workcentre 7220 Firmware
Subscribe
Workcentre 7225
Subscribe
Workcentre 7225 Firmware
Subscribe
Workcentre 7830
Subscribe
Workcentre 7830 Firmware
Subscribe
Workcentre 7835
Subscribe
Workcentre 7835 Firmware
Subscribe
Workcentre 7845
Subscribe
Workcentre 7845 Firmware
Subscribe
Workcentre 7855
Subscribe
Workcentre 7855 Firmware
Subscribe
Workcentre 7970
Subscribe
Workcentre 7970 Firmware
Subscribe
Workcentre 7970i
Subscribe
Workcentre 7970i Firmware
Subscribe
Workcentre Ec7836
Subscribe
Workcentre Ec7836 Firmware
Subscribe
Workcentre Ec7856
Subscribe
Workcentre Ec7856 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30151 | Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:26:16.065Z
Reserved: 2020-02-21T00:00:00
Link: CVE-2020-9330
No data.
Status : Modified
Published: 2020-02-21T23:15:11.497
Modified: 2024-11-21T05:40:25.413
Link: CVE-2020-9330
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD