HIGH · 7.5

CVE-2022-25343

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An unauthenticated attacker, who can send POST requests to the /downl...

Vulnerability Description

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An unauthenticated attacker, who can send POST requests to the /download/set.cgi page by manipulating the failhtmfile variable, is able to cause interruption of the service provided by the Web Application.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
OlivettiD-Color Mf3555 Firmware2xd_s000.002.271
OlivettiD-Color Mf3555-

References

FAQ

What is CVE-2022-25343?

CVE-2022-25343 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An unauthenticated attacker, who can send POST requests to the /downl...

How severe is CVE-2022-25343?

CVE-2022-25343 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-25343?

Check the references section above for vendor advisories and patch information. Affected products include: Olivetti D-Color Mf3555 Firmware, Olivetti D-Color Mf3555.