First published: Thu May 24 2001(Updated: )
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Phaser | =850 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0484 is considered a critical vulnerability due to the lack of authentication for configuration access.
To fix CVE-2001-0484, ensure that access to the configuration pages requires authentication or restrict access through network controls.
Exploiting CVE-2001-0484 can allow attackers to modify device configuration and potentially cause a denial of service.
CVE-2001-0484 specifically affects the Tektronix PhaserLink 850 printer.
Attackers can exploit CVE-2001-0484 by accessing the unprotected configuration pages without authentication.