Xerox Printer Vulnerabilities Enable Credential Capture
ID: 01f438f9-afa5-507f-aaa1-2f6cb5e4257c
STIX ID: report--01f438f9-afa5-507f-aaa1-2f6cb5e4257c
Feed Name: Dark Reading
Two now-patched firmware vulnerabilities (CVE-2024-12510 — LDAP pass-back, CVSS 6.7; and CVE-2024-12511 — SMB/FTP pass-back, CVSS 7.6) in Xerox VersaLink C7025 MFPs permit attackers to change LDAP/SMB/FTP configuration to point to attacker-controlled servers and capture Active Directory credentials; Rapid7 disclosed the issues, Xerox published a firmware update, and recommended mitigations include applying the patch, setting complex admin passwords, avoiding use of elevated Windows accounts (e.g., Domain Admin) for printer LDAP/SMB services, and disabling unauthenticated remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
