// For flags

CVE-2019-13205

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer.

Todos los parámetros de configuración de determinadas impresoras Kyocera (tal y como la ECOSYS M5526cdw versión 2R7_2000.001.701), fueron accesibles para usuarios no autenticados. Esta información sólo se presentaba en los menús cuando se autenticaban, y las páginas que cargaban esta información también estaban protegidas. Sin embargo, todos los archivos que contenían los parámetros de configuración eran accesibles. Estos archivos contenían información confidencial, tales como usuarios, cadenas de la comunidad y otras contraseñas configuradas en la impresora.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-07-03 CVE Reserved
  • 2020-03-13 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Kyocera
Search vendor "Kyocera"
Ecosys M5526cdw Firmware
Search vendor "Kyocera" for product "Ecosys M5526cdw Firmware"
2r7_2000.001.701
Search vendor "Kyocera" for product "Ecosys M5526cdw Firmware" and version "2r7_2000.001.701"
-
Affected
in Kyocera
Search vendor "Kyocera"
Ecosys M5526cdw
Search vendor "Kyocera" for product "Ecosys M5526cdw"
--
Safe