HP MFP Digital Sending Software < 4.18.3 Local Unspecified Authentication Bypass

medium Nessus Plugin ID 46676

Synopsis

The remote Windows host contains an application that is affected by an authentication bypass vulnerability.

Description

The remote Windows host contains a version of HP MFP Digital Sending Software earlier than 4.18.3. Such versions are potentially affected by an unspecified authentication bypass vulnerability.

A local attacker, exploiting this flaw, reportedly can gain unauthorized access to 'Send to email' and other functionalities of an HP Multifunction Peripheral (MFP) that is controlled by the HP Digital Sending Software.

Solution

Upgrade to HP MFP Digital Sending Software 4.18.5 or later.

Note that HP initially recommended upgrading to version 4.18.3. While that version does address the vulnerability, it also introduces a non-security defect and HP now recommends upgrading to version 4.18.5.

See Also

https://www.securityfocus.com/archive/1/511283/30/0/threaded

https://www.securityfocus.com/archive/1/511825/30/0/threaded

Plugin Details

Severity: Medium

ID: 46676

File Name: hp_mfp_dss_4_18_3.nasl

Version: 1.10

Type: local

Agent: windows

Family: Windows

Published: 5/19/2010

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Information

CPE: cpe:/a:hp:multifunction_peripheral_digital_sending_software

Required KB Items: SMB/HP_MFP_DSS/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 5/12/2010

Vulnerability Publication Date: 5/12/2010

Reference Information

CVE: CVE-2010-1558

BID: 40147