CVE-2019-13205
Last modified
CVE-2019-13205 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kyocera | Ecosys M5526cdw Firmware | 2r7_2000.001.701 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13205?
How severe is CVE-2019-13205?
How do I fix CVE-2019-13205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1320An elevation of privilege vulnerability exists when Windows …7.8
- CVE-2019-13200The web application of several Kyocera printers (such as the…6.1
- CVE-2019-13201Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…9.8
- CVE-2019-13202Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…9.8
- CVE-2019-13203Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…8.8
- CVE-2019-13204Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…9.8
- CVE-2019-13206Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.…8.8
- CVE-2019-13207nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buff…
- CVE-2019-13208WavesSysSvc in Waves MAXX Audio allows privilege escalation …
- CVE-2019-13209Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websoc…
- CVE-2019-1321An elevation of privilege vulnerability exists when Windows …7.8
- CVE-2019-13217A heap buffer overflow in the start_decoder function in stb_…7.8
Are you affected by CVE-2019-13205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
