CVE-2021-42642

HIGH

PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the plaintext console username and password for a printer.

Scores

CVSS v3 7.5
EPSS 0.0139
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (2)
printerlogic/web_stack 19.1.1.13 (4 CPE variants)
printerlogic/web_stack < 19.1.1.13
Published Feb 02, 2022
Tracked Since Feb 18, 2026