CVE-2019-13204
https://notcve.org/view.php?id=CVE-2019-13204
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by multiple buffer overflow vulnerabilities in the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS), and potentially execute arbitrary code on the device. Algunas impresoras Kyocera (tal y como la ECOSYS M5526cdw versión 2R7_2000.001.701), fueron afectadas por múltiples vulnerabilidades de desbordamiento de búfer en el servicio IPP. Esto permitiría a un atacante no autenticado causar una Denegación de Servicio (DoS), y potencialmente ejecutar un código arbitrario en el dispositivo. • https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-kyocera-printers • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2019-13205
https://notcve.org/view.php?id=CVE-2019-13205
All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer. Todos los parámetros de configuración de determinadas impresoras Kyocera (tal y como la ECOSYS M5526cdw versión 2R7_2000.001.701), fueron accesibles para usuarios no autenticados. • https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-kyocera-printers • CWE-306: Missing Authentication for Critical Function •
CVE-2019-13206
https://notcve.org/view.php?id=CVE-2019-13206
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in multiple parameters of the Document Boxes functionality of the web application that would allow an authenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device. Algunas impresoras Kyocera (tal y como la ECOSYS M5526cdw versión 2R7_2000.001.701), fueron afectadas por una vulnerabilidad de desbordamiento de búfer en múltiples parámetros de la funcionalidad Document Boxes de la aplicación web que permitiría a un atacante autenticado llevar a cabo un ataque de Denegación de Servicio, bloquear el dispositivo o ejecutar potencialmente un código arbitrario en el dispositivo. • https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-kyocera-printers • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2019-6452
https://notcve.org/view.php?id=CVE-2019-6452
Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password. Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci permiten que atacantes remotos puedan abusar del botón de prueba en la libreta de direcciones de la máquina para obtener una contraseña FTP o SMB de texto simple. • http://www.nccst.nat.gov.tw https://github.com/cvereveal/CVEs/tree/master/CVE-2019-6452 • CWE-522: Insufficiently Protected Credentials •
CVE-2018-16656
https://notcve.org/view.php?id=CVE-2018-16656
DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents of arbitrary users via a modified HTTP request. En DoBox_CstmBox_Info.model.htm en los dispositivos Kyocera TASKalfa versión 4002i y versión 6002i, permite a los atacantes remotos leer los documentos de usuarios arbitrarios por medio de una petición HTTP modificada. • https://mars-cheng.github.io/blog/2019/CVE-2018-16656 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •