CVE-2002-0305
CVSS5.0
发布时间 :2002-05-31 00:00:00
修订时间 :2016-10-17 22:18:47
NMCOS    

[原文]Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.


[CNNVD]ZOT P100s PrintServer Default SNMP默认口令漏洞(CNNVD-200205-127)

        
        ZOT (Zero One Tech) P100s PrintServer是一个硬件,多协议的打印服务器产品。
        P100s PrintServer实现上存在漏洞,可以使过程攻击者获取此打印服务器的相关信息。
        ZOT P100s PrintServer存在一个默认的SNMP口令字,即使在禁止SNMP或把口令值从原来的"public"改为其他值时,通过SNMP客户程序依然能够通过此口令来访问该设备。这个问题可能导致打印服务器的相关信息泄露给远程攻击者,攻击者可能利用这些信息进一步攻击网络。
        

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)

产品及版本信息(CPE)暂不可用

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0305
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2002-0305
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200205-127
(官方数据源) CNNVD

- 其它链接及资源

http://marc.info/?l=bugtraq&m=101432416503293&w=2
(UNKNOWN)  BUGTRAQ  20020221 Zero One Tech (ZOT) P100s PrintServer and SNMP
http://www.securityfocus.com/bid/4155
(UNKNOWN)  BID  4155
http://xforce.iss.net/xforce/xfdb/8270
(UNKNOWN)  XF  zot-default-snmp-string(8270)

- 漏洞信息

ZOT P100s PrintServer Default SNMP默认口令漏洞
中危 设计错误
2002-05-31 00:00:00 2005-10-20 00:00:00
远程  
        
        ZOT (Zero One Tech) P100s PrintServer是一个硬件,多协议的打印服务器产品。
        P100s PrintServer实现上存在漏洞,可以使过程攻击者获取此打印服务器的相关信息。
        ZOT P100s PrintServer存在一个默认的SNMP口令字,即使在禁止SNMP或把口令值从原来的"public"改为其他值时,通过SNMP客户程序依然能够通过此口令来访问该设备。这个问题可能导致打印服务器的相关信息泄露给远程攻击者,攻击者可能利用这些信息进一步攻击网络。
        

- 公告与补丁

        临时解决方法:
        如果您不能立刻安装补丁或者升级,CNNVD建议您采取以下措施以降低威胁:
        * 对SNMP服务端口设置访问控制,只允许可信主机连接访问。
        厂商补丁:
        ZOT
        ---
        目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:
        
        http://www.01tech.com/product_p100s.htm

- 漏洞信息

5775
Zero One Tech P100 SNMP Default String
Remote / Network Access Information Disclosure
Loss of Confidentiality
Exploit Public

- 漏洞描述

Zero One Technology Print Server P100 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when SNMP is disabled on the device and an SNMP walk occurs, which will disclose SNMP information resulting in a loss of confidentiality.

- 时间线

2002-02-21 Unknow
Unknow Unknow

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

- 相关参考

- 漏洞作者

- 漏洞信息

ZOT P100s PrintServer Default SNMP Community String Vulnerability
Design Error 4155
Yes No
2002-02-21 12:00:00 2009-07-11 10:56:00
This issue was submitted to BugTraq on February 21st, 2002 by Clinton Smith <security@esales.iinet.net.au>.

- 受影响的程序版本

Zero One Tech P100s PrintServer 5.31.13 E

- 漏洞讨论

ZOT (Zero One Tech) P100s PrintServer is a hardware, multi-protocol print server product.

ZOT P100s PrintServer has a default public SNMP community read string. Furthermore, this string is reportedly still accessible via a SNMP client even if the user has disabled SNMP or changed the value from the default of "public".

This issue may cause information about the configuration of the device to be leaked to a remote attacker. Information about the network may also be disclosed in this manner.

An attacker may use this information to mount further attacks against the device and/or network.

- 漏洞利用

This issue may be exploited using a SNMP client.

- 解决方案

Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>.

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站