Adversaries exploiting unpatched vulnerabilities become a constant security concern for organizations. Cybersecurity researchers from F-Secure recently discovered multiple critical vulnerabilities in 150 multifunction printers (MFPs) manufactured by Hewlett Packard (HP). The researchers stated the security flaws CVE-2021-39237 and CVE-2021-39238 could enable a remote attacker to take full control of the vulnerable devices, steal information, and further infiltrate networks to inflict other types of damage. The vulnerabilities, dating back to 2013, are now fixed after HP issued security patches.
The security flaws could allow an attacker to launch a cross-site printing attack on the vulnerable printers’ network. The attacker would first need to trick a victim into visiting a malicious website. The cross-site printing attack involves tricking users from a targeted organization into visiting a malicious website, exposing the organization’s vulnerable MFPs. Once the victim visits the malicious site, the website automatically prints a document containing a maliciously-crafted font on the vulnerable MFP, giving the attacker code execution rights on the device.
Also Read: How Cross-Site Scripting Attacks Work and How to Prevent Them
“An attacker with these code execution rights could silently steal any information ran (or cached) through the MFP. This includes not only documents that are printed, scanned, or faxed but also information like passwords and login credentials that connect the device to the rest of the network. Attackers could also use compromised MFPs as a beachhead to penetrate further into an organization’s network to pursue other objectives (such as stealing or changing other data, spreading ransomware, etc.),“ the researchers said.
With HP being one of the leading providers of MFPs, many organizations worldwide are likely using vulnerable devices.
While there is no information on exploited vulnerabilities, F-Secure urged organizations to fix their vulnerable MFPs. In addition to patching, the company provided certain measures to secure MFPs against unauthorized intrusions. These include:
“It’s easy to forget that modern MFPs are fully-functional computers that threat actors can compromise just like other workstations and endpoints. And just like other endpoints, attackers can leverage a compromised device to damage an organization’s infrastructure and operations. Experienced threat actors see unsecured devices as opportunities, so organizations that don’t prioritize securing their MFPs like other endpoints leave themselves exposed to attacks like the ones documented in our research,” said F-Secure security consultant Timo Hirvonen.
The post Security Vulnerabilities Discovered in HP’s 150 Multi-function Printers appeared first on CISO MAG | Cyber Security Magazine.
Click to Open Code Editor