LDAP Credential Exposure Risk in Xerox WorkCentre Printers
CVE-2020-9330
8.8HIGH
Summary
Certain Xerox WorkCentre printers prior to version 073.xxx.000.02300 lack a mechanism to require revalidation of LDAP bind credentials when the LDAP connector IP address is altered. This flaw allows an attacker, who may exploit default credentials to gain access, to change the LDAP connection IP to a malicious server. Consequently, any subsequent authentication attempts would transmit plaintext LDAP credentials to the attacker. While these credentials may belong to non-privileged users, it is common practice for organizations to use service accounts with elevated privileges for LDAP binds, potentially affording attackers significant control over the Active Directory domain.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved