CVE-2014-9002: Critical severity lantronix xprintserver firmware vulnerability
Published Nov 20, 2014
·Updated
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.
Affected Software
1 affected component
Lantronix xPrintServer
Event History
Nov 20, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9002?
CVE-2014-9002 is classified as a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2014-9002?
To fix CVE-2014-9002, update the Lantronix xPrintServer to the latest firmware version provided by the manufacturer.
3
What type of attacks can occur due to CVE-2014-9002?
CVE-2014-9002 allows remote attackers to execute arbitrary commands on the affected device.
4
Which software is affected by CVE-2014-9002?
CVE-2014-9002 affects the Lantronix xPrintServer firmware across all versions.
5
Is CVE-2014-9002 exploitable without authentication?
Yes, CVE-2014-9002 can be exploited remotely without requiring any form of authentication.