CVE-2023-4957: Authentication Bypass on Zebra ZTC
A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this authentication bypass vulnerability?
The vulnerability ID of this authentication bypass vulnerability is CVE-2023-4957.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Zebra Zt410 Firmware.
How severe is CVE-2023-4957?
CVE-2023-4957 has a severity rating of medium with a score of 4.3.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a specially crafted POST request to the Zebra ZTC ZT410-203dpi ZPL printer in the same network, allowing them to change the username and password for the Web Page.
Is there a fix available for this vulnerability?
Please refer to the vendor's security advisory for information on available fixes for CVE-2023-4957.