CVE-2019-13170: CSRF
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Xerox printer vulnerability?
The vulnerability ID for this Xerox printer vulnerability is CVE-2019-13170.
Which Xerox printers are affected by this vulnerability?
Some Xerox printers, such as the Phaser 3320 V53.006.16.000 firmware version, are affected by this vulnerability.
What is the impact of this vulnerability?
Successful exploitation of this vulnerability can lead to the takeover of a local account on the affected Xerox printer.
Is there a fix available for this vulnerability?
Please refer to the Xerox website or contact Xerox for information on available fixes for this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Xerox security website and the NCC Group technical advisory.