Otkriven je sigurnosni nedostatak u paketu HP MFP Digital Sending Software za operacijske sustave Windows. Ovaj paket se koristi za slanje skeniranih dokumenata na različita odredišta poput FTP poslužitelja, pisača ili e-mail adresu. Nisu objavljeni uzroci samog propusta, ali je poznato da ga lokalni napadač može iskoristiti za pristup uređajima preko Digital Sending Software paketa bez autentikacije. Za sada nije dostupna nadogradnja kojom se otklanja nedostatak, nego se preporuča uključivanje autentikacije pomoću "Configuration Template" funkcionalnosti.

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02738104

Version: 1
HPSBPI02640 SSRT100410 rev.1 - HP MFP Digital Sending Software Running on Windows, Authentication Bypass
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2011-03-02

Last Updated: 2011-03-02

Potential Security Impact: Authentication bypass

Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY

A potential security vulnerability has been identified with HP MFP Digital Sending Software running on Windows. The vulnerability could cause authentication to be disabled for managed devices. This could allow access to the devices from the Digital Sending Software without authentication.

References: CVE-2011-0279
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP MFP Digital Sending Software v4.91.00
BACKGROUND

For a PGP signed version of this security bulletin please write to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.

CVSS 2.0 Base Metrics
Reference
	
Base Vector
	
Base Score
CVE-2011-0279
	
(AV:L/AC:M/Au:S/C:P/I:P/A:P)
	
4.1

Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.
RESOLUTION

Until a new version of HP MFP Digital Sending Software is available the vulnerability can be avoided as follows.

When using the Configuration Template feature added in version 4.91 of the HP MFP Digital Sending Software,

   1. Insure that authentication is specified in all device templates
   2. Reconfigure all devices previously configured using templates with these revised templates

Note: The procedure above is needed only if

    * Authentication is required
    * A device had previously been configured using a template that did not include authentication settings

HISTORY
Version:1 (rev.1) - 2 March 2011 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.
Report: To report a potential security vulnerability with any HP supported product, send Email to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information.
To get the security-alert PGP key, please send an e-mail message as follows:
  To: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
  Subject: get key

Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email:
http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC
On the web page: ITRC security bulletins and patch sign-up
Under Step1: your ITRC security bulletins and patches
    -check ALL categories for which alerts are required and continue.
Under Step2: your ITRC operating systems
    -verify your operating system selections are checked and save.

To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php
Log in on the web page: Subscriber's choice for Business: sign-in.
On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections.

To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 

Idi na vrh