9.1

CVE-2021-42640

Exploit
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Printerlogic ≫ Web Stack Version < 19.1.1.13
Printerlogic ≫ Web Stack Version 19.1.1.13 Update -
Printerlogic ≫ Web Stack Version 19.1.1.13 Update sp2
Printerlogic ≫ Web Stack Version 19.1.1.13 Update sp3-3
Printerlogic ≫ Web Stack Version 19.1.1.13 Update sp9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.03% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://portswigger.net/daily-swig/printerlogic-vendor-addresses-triple-rce-threat-against-all-connected-endpoints
Third Party Advisory
https://securityaffairs.co/wordpress/127194/security/printerlogic-printer-management-suite-flaws.html
Third Party Advisory
https://www.printerlogic.com/security-bulletin/
Vendor Advisory
https://www.securityweek.com/printerlogic-patches-code-execution-flaws-printer-management-suite
Third Party Advisory
https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-printerlogic-issues-security-alert/
Third Party Advisory
Exploit
https://thecyberthrone.in/2022/01/26/printerlogic-%F0%9F%96%A8-fixes-critical-vulnerabilities-in-its-suite/?utm_source=rss&utm_medium=rss&utm_campaign=printerlogic-%25f0%259f%2596%25a8-fixes-critical-vulnerabilities-in-its-suite
Third Party Advisory