Security Market Segment LS
Thursday, 29 November 2012 08:54

Samsung offers workaround for printer SNMP security issue

By

Disabling SNMP may mitigate a security vulnerability in Samsung printers until revised firmware is available.

Yesterday we reported on a vulnerability in Samsung's networked printers.

Samsung has provided the following statement:

Samsung is aware of and has resolved the security issue affecting Samsung network printers and multifunction devices. The issue affects devices only when SNMP is enabled, and is resolved by disabling SNMP.

We take all matters of security very seriously and we are not aware of any customers who have been affected by this vulnerability. Samsung is committed to releasing updated firmware for all current models by November 30, with all other models receiving an update by the end of the year. However, for customers that are concerned, we encourage them to disable SNMPv1,2 or use the secure SNMPv3 mode until the firmware updates are made.

For further information, customers may contact Samsung customer service at 1-866-SAM4BIZ for business customers or 1-800-SAMSUNG for consumers.

Those phone numbers aren't much help if you're outside the US. Samsung appears to have a single customer service number in Australia: 1300 362 603.

The CERT vulnerability note says the problem revolves around "a hardcoded SNMP full read-write community string that remains active even when SNMP is disabled in the printer management utility" while Samsung says "The issue affects devices only when SNMP is enabled, and is resolved by disabling SNMP."

If disabling SNMP really does protect against the vulnerability, that would be no great loss for practically all home users or any organisation that doesn't use SNMP to monitor their network.

Security experts often recommend disabling any functions that are not required in order to reduce the attack surface - if a function is not available, an attacker will be unable to exploit its vulnerabilities.

When we checked the support pages for a few current Samsung network printers this morning, we found no mention of the issue or the firmware updates - presumably they will be there by tomorrow, November 30.


Subscribe to Newsletter here

NEW OFFER - ITWIRE LAUNCHES PROMOTIONAL NEWS & CONTENT

Recently iTWire remodelled and relaunched how we approach "Sponsored Content" and this is now referred to as "Promotional News and Content”.

This repositioning of our promotional stories has come about due to customer focus groups and their feedback from PR firms, bloggers and advertising firms.

Your Promotional story will be prominently displayed on the Home Page.

We will also provide you with a second post that will be displayed on every page on the right hand side for at least 6 weeks and also it will appear for 4 weeks in the newsletter every day that goes to 75,000 readers twice daily.

POST YOUR NEWS ON ITWIRE NOW!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

These days our customers Advertising & Marketing campaigns are mainly focussed on Webinars.

If you wish to promote a Webinar we recommend at least a 2 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://www.itwire.com/itwire-update.html and Promotional News & Editorial.

For covid-19 assistance we have extended terms, a Webinar Business Booster Pack and other supportive programs.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Stephen Withers

joomla visitors

Stephen Withers is one of Australia¹s most experienced IT journalists, having begun his career in the days of 8-bit 'microcomputers'. He covers the gamut from gadgets to enterprise systems. In previous lives he has been an academic, a systems programmer, an IT support manager, and an online services manager. Stephen holds an honours degree in Management Sciences and a PhD in Industrial and Business Studies.

BACK TO HOME PAGE

ZOOM WEBINARS & ONLINE EVENTS

GUEST ARTICLES

VENDOR NEWS

Guest Opinion

Guest Interviews

Guest Research & Case Studies

Channel News

Comments