CVE-2008-0374

OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:oki:c5510mfp_firmware:1.01:*:*:*:*:*:*:*
cpe:2.3:h:oki:c5510mfp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 00:41

Type Values Removed Values Added
References () http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory () http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory
References () http://securityreason.com/securityalert/3569 - Third Party Advisory () http://securityreason.com/securityalert/3569 - Third Party Advisory
References () http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link () http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link
References () http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry

25 Jan 2024, 20:41

Type Values Removed Values Added
CWE CWE-310 CWE-319
CPE cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:pu_01.03.01:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:web_page_1.00:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:cu_h2.15:*:*:*:*:*:*:*
cpe:2.3:h:oki_printing_solutions:c5510_mfp_printer:system_fw_1.01:*:*:*:*:*:*:*
cpe:2.3:h:oki:c5510mfp:-:*:*:*:*:*:*:*
cpe:2.3:o:oki:c5510mfp_firmware:1.01:*:*:*:*:*:*:*
CVSS v2 : 10.0
v3 : unknown
v2 : 10.0
v3 : 7.5
References (BUGTRAQ) http://www.securityfocus.com/archive/1/486511/100/0/threaded - (BUGTRAQ) http://www.securityfocus.com/archive/1/486511/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References (BID) http://www.securityfocus.com/bid/27339 - (BID) http://www.securityfocus.com/bid/27339 - Broken Link, Third Party Advisory, VDB Entry
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/39775 - VDB Entry
References (MISC) http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - (MISC) http://www.csnc.ch/en/modules/news/news_0004.html_1394092626.html - Broken Link
References (SECUNIA) http://secunia.com/advisories/28553 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/28553 - Broken Link, Vendor Advisory
References (SREASON) http://securityreason.com/securityalert/3569 - (SREASON) http://securityreason.com/securityalert/3569 - Third Party Advisory

Information

Published : 2008-01-22 20:00

Updated : 2025-04-09 00:30


NVD link : CVE-2008-0374

Mitre link : CVE-2008-0374

CVE.ORG link : CVE-2008-0374


JSON object : View

Products Affected

oki

  • c5510mfp_firmware
  • c5510mfp
CWE
CWE-319

Cleartext Transmission of Sensitive Information