HOMEVULNERABILITIESCVE-2019-10960
HIGH

CVE-2019-10960

CWE-522Published: August 20, 2019· Updated: Jun 17, 2026

7.5
CVSS v3.1

Official Description

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

NVD Source

Technical Analysis

CVE-2019-10960 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), with a CVSS base score of 7.5.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityNone
AvailabilityNone
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Vendors & Products

zebra16 product(s)
zt610 firmwarezt610zt620 firmwarezt620zt510 firmwarezt510zt410 firmwarezt410zt420 firmwarezt420zt220 firmwarezt220+4
Source: NVD CPE · 16 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (2)

https://www.us-cert.gov/ics/advisories/icsa-19-232-01Mitigation · Third Party Advisory · US Government Resource
https://www.us-cert.gov/ics/advisories/icsa-19-232-01Mitigation · Third Party Advisory · US Government Resource

Quick Facts

CVE IDCVE-2019-10960
CVSS Score7.5 / 10
SeverityHIGH
WeaknessCWE-522
CISA KEVNo
Affected1 vendor(s)
PublishedAug 20, 2019

Related CVEs (CWE-522)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2019-10960 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.