HIGH · 7.5

CVE-2019-10960

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front pan...

Vulnerability Description

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ZebraZt610 FirmwareAll versions
ZebraZt610All versions
ZebraZt620 FirmwareAll versions
ZebraZt620All versions
ZebraZt510 FirmwareAll versions
ZebraZt510All versions
ZebraZt410 FirmwareAll versions
ZebraZt410All versions
ZebraZt420 FirmwareAll versions
ZebraZt420All versions
ZebraZt220 FirmwareAll versions
ZebraZt220All versions
ZebraZt230 FirmwareAll versions
ZebraZt230All versions
Zebra220Xi4 FirmwareAll versions
Zebra220Xi4All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10960?

CVE-2019-10960 is a vulnerability with a CVSS score of 7.5 (HIGH). Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front pan...

How severe is CVE-2019-10960?

CVE-2019-10960 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10960?

Check the references section above for vendor advisories and patch information. Affected products include: Zebra Zt610 Firmware, Zebra Zt610, Zebra Zt620 Firmware, Zebra Zt620, Zebra Zt510 Firmware.