CVE-2021-42913

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
20/12/2021
Last modified:
07/11/2023

Description

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:samsung:scx-6555:-:*:*:*:*:*:*:*
cpe:2.3:h:samsung:scx-6555n:-:*:*:*:*:*:*:*
cpe:2.3:a:samsung:syncthru_web_service:-:*:*:*:*:*:*:*