CVE-2019-13166: High severity xerox phaser 3320 firmware vulnerability
Published Mar 13, 2020
·Updated
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
Affected Software
2 affected components
Xerox Phaser 3320 Firmware=v53.006.16.000
Xerox Phaser 3320
Event History
Mar 13, 2020
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
Description
Frequently Asked Questions
1
What is CVE-2019-13166?
CVE-2019-13166 is a vulnerability found in some Xerox printers (such as the Phaser 3320 V53.006.16.000) where account lockout is not implemented, allowing unauthorized access.
2
How severe is CVE-2019-13166?
CVE-2019-13166 has a severity rating of 7.5 (High).
3
Which Xerox printers are affected by CVE-2019-13166?
Xerox Phaser 3320 Firmware v53.006.16.000 is affected by CVE-2019-13166.
4
How can an attacker exploit CVE-2019-13166?
An attacker can exploit CVE-2019-13166 by performing brute force guessing attacks to extract local account credentials from the vulnerable Xerox printers.
5
Are there any fixes or patches available for CVE-2019-13166?
Please refer to the vendor's website for details on available fixes or patches for CVE-2019-13166.