Question : Printer Vulnerability Assessment

Hi Pals,

  Okay here is one I am looking for different thoughts. Say I have around 500 Networked Multi-Function Printers and I want to do a Security Assessment for them. What are the obvious ways/references and some tools if possible ? This is a little different to me as I need to know the way to approach the problem.

  Thnx in Advance.

Cheers,
Rajesh

Answer : Printer Vulnerability Assessment

I recommend that you search under "multifunction printer" in the Mitre Common Vulnerability and Exposures List. (The CVE list)
A quick search turns up 34 items that relate to MF machines by various manufacturers.
Get to the list at this URL:
http://cve.mitre.org/cve/

I think doing an assessment on your own would be challenging.
Owing to the size of the footprint, the manufacturer might be able to provide
you with their own internal test results - if they have any. Your VAR may have
appropriate channels to get support from the OEM.

If you are looking for references, you might find something in the SANS courses or in
their reading room. www.sans.org

Failing all of the above, you could contract with a security firm to perform an
assessment for you. Some of the CVE's above may have been generated by security
firms with the appropriate expertise.

Best,

Rich
Random Solutions  
 
programming4us programming4us