
Security researcher Brendan O'Connor has made a public presentation at the Black Hat conference in Las Vegas detailing how to exploit a vulnerability residing in Xerox's WorkCenter multifunction
printers. The disclosed security flaw allows attackers to execute unauthorized programs on the affected printers and access the data involved in the printing process. With an exploit of such a level, O'Connor demonstrated that the network traffic could easily be disrupted or even completely compromised.
"Think of all the sensitive data that's going through these," O'Connor said. "Everybody prints and there's an inherent trust in these types of devices." The white-hacker stated that his demonstration of the hacking was meant to draw the spot light on the security issues inherent with embedded devices. He also stated that because of the large scale of printer device implementation at both corporate and home levels, the vulnerabilities could spark an epidemic of exploits.
Armon Rahgozar, a manager with Xerox's solutions and partnership technology office claimed that Xerox had already addressed the vulnerability with security bulletins released at the beginning of the year for WorkCenter and WorkCenter Pro series 200 devices, but O'Connor's demonstration proved him wrong.
Xerox also stated that it is going to introduce an automatic update system to push future security updates over the Internet.