Path Traversal Bug Besets Popular Kyocera Office Printers
ID: fbe6a33d-95c5-52a3-ade2-9558c7ef99ce
STIX ID: report--fbe6a33d-95c5-52a3-ade2-9558c7ef99ce
Feed Name: Dark Reading
Threat Score
A newly disclosed vulnerability (CVE-2023-50916) in Kyocera Device Manager allows an attacker who can intercept web requests to coerce the application into using a UNC path, redirect authentication attempts to an attacker-controlled server, and capture service-level credentials; Kyocera has released a patch, the flaw has not been seen exploited in the wild, and its impact depends on network access and how service accounts are configured.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
