Minor security problem in Axis 560x web interface

From: Ian Vitek (ian.vitek_at_as5-5-7.bi.s.bonet.se)
Date: 07/03/03

  • Next message: Spybreak: "Generic way to exploit an insecure /tmp file creation - Red Hat 7,8,9 (Re: Red Hat 9: free tickets)"
    Date: Thu, 3 Jul 2003 11:27:47 +0200 (CEST)
    To: <vulndiscuss@vulnwatch.org>
    To: <vuln-dev@securityfocus.com>
    To: <hackers-se@cqure.net>
    
    

    There seems to be a minor security problem with the web interface of Axis printservers.

    Type of vulnerability:
      Denial of service

    Affected Software:
      Web interface of Axis Print Server 560 and 5600

    Verified Version:
      6.10, 6.15, 6.20

    Unaffected Version?
      5.x

    Background and problem description
    ==================================
    The web interface of the Axis print server 560 and 5600 hangs/crashes if it recieves a special http request.
    It is not verified if it is the printer server or just the web interface that hangs/crashes.

    URL to try:
    http://ps/u_server.shtm?port=a_server.shtm
    http://ps/u_server.shtm?port=<!--
    http://ps/?_

    Vendor contacted 26/6-2003.
    Axis response:
    ----------
    Please update to the latest firmware. There is no firmware 6.10 for the Axis 560, it must be different product. The latest firmware should not have any security vulnerability issues.

    Downloads are available on FTP: ftp://ftp.axis.com/pub_soft/prt_srv/
    ----------
    (Version 6.10 is not the firmware version. It is probably the web interface version.)

    Can anyone confirm this?

    To all of my friends; The Beach in Vegas Sunday 3/8-2003?
    //Ian Vitek


  • Next message: Spybreak: "Generic way to exploit an insecure /tmp file creation - Red Hat 7,8,9 (Re: Red Hat 9: free tickets)"

    Relevant Pages

    • Motorola WA840G v1 only .... replacement firmware instructions
      ... however there were very brief install instructions for the ... As I upgraded from Motorola's latest firmware 6.1.4) avail from ... the currently installed Motorola web interface to flash the image fine. ...
      (alt.internet.wireless)
    • Re: Why are Cisco routers so expensive? - oh, and fiber-optics. Why not?
      ... As do several other "domestic" routers, ... I suspect your right about the dodgy components, I think my one has dodgy ... locking up earlier this year, mostly when I tried to access the web interface, ... I noticed while examining the firmware, ...
      (uk.telecom.broadband)
    • Re: OT: LInksys router BEFSR41 dead... anything i can do?
      ... Both links have the firmware file and also have a "setup wizard" app ... firmware without needing the web interface - just make ... >>called Linksys and got the answer that I had to buy another router, ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • Upgrading firmware (1.1 to 1.8) on BT Voyager 2005 ADSL modem - Web interface broken
      ... would like to try a firmware upgrade on her Voyager 205 modem. ... She is using a BT Voyager 205 as supplied by BT. ... Web interface where I can load the new firmware - the page just can't ...
      (uk.telecom.broadband)
    • Re: Printserver und LPT1:
      ... Neueste Firmware drauf? ... Früher haben wir AddPrinter 1.01 und AutoGo 1.22 benutzt, ... Das ist zwar eigentlich für den AXIS OfficeBasic, ... Bitte NUR in der Newsgroup antworten! ...
      (microsoft.public.de.german.win2000.networking)

  • Quantcast