Xerox representatives revealed a dangerous vulnerability in their equipment. It was first discovered a year and a half ago. However, the company's specialists were hesitant to disclose the bug because it was considered a particularly dangerous vulnerability and could have affected a large number of devices. This bug significantly impacted the company's information security.
What is known about the vulnerability, information security lecture course Moscow
First and foremost, Xerox is one of the world's leading manufacturers of office equipment. The company also creates printers, scanners, and copiers for the home. This high-quality equipment has a long service life, making it a popular choice for users worldwide. It was precisely because of the popularity of Xerox equipment that experts were alarmed by the discovery of the vulnerability. This means that the information security of millions of users worldwide is compromised.
Apparently, the vulnerability allowed an attacker to trigger a DoS error on the device, causing it to virtually stop working. When the bug was triggered, the printer automatically rebooted, but the error persisted. It then required a forced reboot again. This made the printer completely unusable. Furthermore, the researchers were concerned about how easy it was to reproduce the bug.
In this case, the vulnerability algorithm was launched using a file with a certain extension type. And it looked like this:
- The printer copied the file to define the print resources;
- a faulty file triggered a DoS error;
- the error required an automatic reboot;
- After turning on the printer tried to print the last file from the queue.
Unfortunately, even an experienced user could not interrupt such a cycle on their own. To do this, it was necessary to take a number of specific steps. And also to understand the features of the printers of a particular model.
Why was the vulnerability kept quiet for so long?
The bug was discovered back in 2019. However, the specialists who discovered the problem immediately contacted Xerox management directly. They, in turn, asked that the vulnerability not be made public. It turned out that it affected several extremely popular printer models. This meant that once the bug was made public, all devices would be at risk. Consequently, the information security of many companies would be compromised.
Of course, this could not be allowed. Therefore, Xerox developers began to study the problem in depth to solve it once and for all. They had enough time, since the hackers did not know about the new bug. As a result, this approach bore fruit. And already in 2020, Xerox developers were able to release a new patch. But this was not enough to protect all equipment. After all, everyone knows that administrators often neglect new patches. Since they can worsen the operation of specific devices.
It took another year and a half for specialists to get most users to install the patch. So, only now have they disclosed the vulnerability. Just in case, the researchers also published information on how to temporarily fix the printer's bug. This required gaining physical access to the device and performing a few simple steps. As a result, Xerox's information security at Moscow's advanced training courses remained at a high level.
SEDICOMM University Team : Cisco Academy , Linux Professional Institute , Python Institute.

