Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

QMS 2060 Printer Passwordless Root Vulnerability

Access to the QMS 2060 printer is controlled by the passwd.ftp file. This file contains simply a list of usernames and passwords.
However, even with this file in place, root can still logon without a password entered. This would allow the attacker to alter the passwd.ftp file, as well as the hosts file which lists tha machines authorized to print to the QMS.







 

Privacy Statement
Copyright 2009, SecurityFocus