Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6780 | MFD02.004 | SV-7002r2_rule | Medium |
Description |
---|
MFD devices or printers utilizing old firmware can expose the network to known vulnerabilities leading to a denial of service or a compromise of sensitive data. While the MFD must use the most current firmware available, it must not use a “call-home” feature that is not allowed. |
STIG | Date |
---|---|
Multifunction Device and Network Printers STIG | 2019-01-04 |
Check Text ( C-2965r2_chk ) |
---|
The reviewer will verify that the MFD or Network Printer are flash upgradeable and are configured to use the most current firmware available. Ensure any “call-home” feature is disabled. If the MFD or Network Printer is not flash upgradeable, this is a finding. If the MFD or Network Printer is not configured with the most current firmware, this is a finding. If the MFD or Network Printer has the “call-home” feature enabled, this is a finding. |
Fix Text (F-6433r2_fix) |
---|
If the MFD or printer cannot be upgraded replace it. If the MFD or printer can be upgraded but is not using the latest release of the firmware, upgrade the firmware. |