Vulnerability Description
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Printerlogic | Web Stack | < 19.1.1.13 |
Related Weaknesses (CWE)
References
- http://printerlogic.comProduct
- https://portswigger.net/daily-swig/printerlogic-vendor-addresses-triple-rce-threNot Applicable
- https://securityaffairs.co/wordpress/127194/security/printerlogic-printer-manageThird Party Advisory
- https://thecyberthrone.in/2022/01/26/printerlogic-%F0%9F%96%A8-fixes-critical-vuThird Party Advisory
- https://www.printerlogic.com/security-bulletin/Vendor Advisory
- https://www.securityweek.com/printerlogic-patches-code-execution-flaws-printer-mThird Party Advisory
- https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-printerlogicExploitThird Party Advisory
- http://printerlogic.comProduct
- https://portswigger.net/daily-swig/printerlogic-vendor-addresses-triple-rce-threNot Applicable
- https://securityaffairs.co/wordpress/127194/security/printerlogic-printer-manageThird Party Advisory
- https://thecyberthrone.in/2022/01/26/printerlogic-%F0%9F%96%A8-fixes-critical-vuThird Party Advisory
- https://www.printerlogic.com/security-bulletin/Vendor Advisory
- https://www.securityweek.com/printerlogic-patches-code-execution-flaws-printer-mThird Party Advisory
- https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-printerlogicExploitThird Party Advisory
FAQ
What is CVE-2021-42637?
CVE-2021-42637 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.
How severe is CVE-2021-42637?
CVE-2021-42637 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-42637?
Check the references section above for vendor advisories and patch information. Affected products include: Printerlogic Web Stack.