Lantronix xPrintServer Arbitrary Command Execution Vulnerability (CVE-2014-9002)
Lantronix xPrintServer Arbitrary Command Execution Vulnerability (CVE-2014-9002)
Release date:
Updated on:
Affected Systems:
Lantronix xPrintServer <5.0.1-65
Description:
CVE (CAN) ID: CVE-2014-9002
Lantronix xPrintServer is a plug-and-play mobile printing server solution.
Lantronix xPrintServer device, firmware versions earlier than 5.0.1-65, does not properly restrict access to ips/. Remote attackers can exploit this vulnerability to execute arbitrary commands through the c parameter in rpc operations.
<* Source: Garret Wassermann
Link: http://www.kb.cert.org/vuls/id/785823
*>
Suggestion:
Vendor patch:
Lantronix
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.lantronix.com/
Refer:
Http://seclists.org/fulldisclosure/2014/Nov/24
Https://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2014-9002
Https://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2014-9003
This article permanently updates the link address: