CVE-1999-1343: Medium severity Xerox Docucolor 4lp vulnerability
HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the embedded HTTP/web management interface is not required, disable the HTTP service via the device administration settings to remove remote exposure.
Xerox DocuColor 4 LP HTTP server HTTP service = disabled if not required - Compensating control
Restrict network access to the printer's HTTP/web management interface with firewall rules, ACLs or network segmentation (management VLAN) so only trusted administrators or VPN users can reach it.
- Operational
If the device becomes unresponsive (hangs) due to this issue, isolate it from the network and reboot the device. Keep it isolated until administrative access is secured (see other actions) and monitor for recurrence.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1343?
CVE-1999-1343 has been classified as a denial of service vulnerability.
How do I fix CVE-1999-1343?
To mitigate CVE-1999-1343, avoid using long URLs that contain an excessive number of '.' characters when interacting with the Xerox DocuColor 4 LP.
What systems are affected by CVE-1999-1343?
CVE-1999-1343 specifically affects the Xerox DocuColor 4 LP HTTP server.
What kind of attack does CVE-1999-1343 enable?
CVE-1999-1343 allows remote attackers to cause a denial of service by hanging the server.
What is the nature of the vulnerability described in CVE-1999-1343?
The nature of the vulnerability in CVE-1999-1343 is related to handling long URLs by the HTTP server.