logo

Path Traversal Bug Besets Popular Kyocera Office Printers

ID: fbe6a33d-95c5-52a3-ade2-9558c7ef99ce

STIX ID: report--fbe6a33d-95c5-52a3-ade2-9558c7ef99ce

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-01-09

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A newly disclosed vulnerability (CVE-2023-50916) in Kyocera Device Manager allows an attacker who can intercept web requests to coerce the application into using a UNC path, redirect authentication attempts to an attacker-controlled server, and capture service-level credentials; Kyocera has released a patch, the flaw has not been seen exploited in the wild, and its impact depends on network access and how service accounts are configured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.