J-Security Center

Title: Tektronix PhaserLink Webserver Vulnerability

Severity: MODERATE

Description:

Certain versions of the Tektronix PhaserLink printer ship with a webserver designed to help facilitate configuration of the device. This service is essentially administrator level access as it can completely modify the system characteristics, restart the machine, asign services etc.

In at least one version of this printer there are a series of undocumented URL's which will allow remote users to retrieve the administrator password. Once the password is obtained by the user, they can manipulate the printer in any way they see fit.

Affected Products:

  • Tektronix Phaser Network Printer 740
  • Tektronix Phaser Network Printer 750
  • Tektronix Phaser Network Printer 750DP
  • Tektronix Phaser Network Printer 840
  • Tektronix Phaser Network Printer 930

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.