Researchers Reveal 35 Flaws in Six Printers

Researchers Reveal 35 Flaws in Six Printers

Researchers at NCC Group have uncovered 35 “significant” vulnerabilities in models from six popular enterprise printer brands.





The risk mitigation consultancy tested kit produced by HP, Ricoh, Xerox, Lexmark, Kyocera and Brother – with security advisories for each published as of today.





It claimed to have been able to find the flaws using “basic tools,” some of which date back 30-40 years. The firm added that some bugs were uncovered within mere minutes.





They include buffer overflows, cross-site scripting, denial of service, information disclosure and other flaws as well as hard-coded credentials and broken access controls.





All of the vulnerabilities discovered have now been patched or are in the process of being fixed and system administrators are urged to update the affected models to the latest firmware.





“Because printers have been around for decades, they’re not typically regarded as enterprise IoT, yet they are embedded devices that connect to sensitive corporate networks, and therefore demonstrate the potential risks and security vulnerability posed by enterprise IoT,” argued Matt Lewis, research director at NCC Group.





“Building security into the development lifecycle would mitigate most, if ..

Support the originator by clicking the read the rest link below.