Vulnerability Description
IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ippusbxd Project | Ippusbxd | <= 1.21.2 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2015/08/11/1
- http://www.openwall.com/lists/oss-security/2015/08/18/11
- http://www.ubuntu.com/usn/USN-2725-1
- https://bugs.launchpad.net/ubuntu/+source/ippusbxd/+bug/1455644Vendor Advisory
- https://github.com/tillkamppeter/ippusbxd/commit/46844402bca7a38fc224483ba6f0a93
- http://www.openwall.com/lists/oss-security/2015/08/11/1
- http://www.openwall.com/lists/oss-security/2015/08/18/11
- http://www.ubuntu.com/usn/USN-2725-1
- https://bugs.launchpad.net/ubuntu/+source/ippusbxd/+bug/1455644Vendor Advisory
- https://github.com/tillkamppeter/ippusbxd/commit/46844402bca7a38fc224483ba6f0a93
FAQ
What is CVE-2015-6520?
CVE-2015-6520 is a vulnerability with a CVSS score of 7.5 (HIGH). IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request.
How severe is CVE-2015-6520?
CVE-2015-6520 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6520?
Check the references section above for vendor advisories and patch information. Affected products include: Ippusbxd Project Ippusbxd.