➢ Added support for G&D FIPS-201 SIPR smartcards that are provisioned without
encipherment certificates.
➢ When logging into the Embedded Web Server using Windows authentication, you
may not be able to see all the tabs or options that you have been granted access
to.
➢ This firmware addresses the following security issues: CVE-2017-13077:
Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.
CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.
CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way
handshake. CVE-2017-13080: Reinstallation of the group key (GTK) in the group
key handshake. CVE-2017-13081: Reinstallation of the integrity group key (IGTK)
in the group key handshake.
➢ This firmware disables the "TFTP Configuration File" setting to prevent
unauthorized device resets.
Embedded JetDirect:
➢ Fixed "IP Address/Subnet is out of range. Check the field. IP=x.x.x.x
Mask=x.x.x.x" error given when an IP address was entered with zero for the host
number in the Access Control List.
➢ Buffers expanded to hold large DNS responses (70+ records). Previously only
about 7 or 8 records were accepted.
➢ Trying to connect via the FTP may fail with certain applications.
➢ Fixed an issue where Windows Authentication would hang the printer.
➢ Product was generating Certificate Signing Requests with version number other
than zero. RFC 2986 requires a version number of zero.
➢ Product was generating Certificate Signing Requests with version number other
than zero. RFC 2986 requires a version number of zero.
➢ Printer crashes with 81.09.00 Embedded Jetdirect Error message when user sets
Admin password from Telnet.
➢ Under certain circumstances during initial power-on, the DCHP Discover message
is sent without a hostname (option 81). This fix ensures that option 81 is always
present when applicable.
➢ The password input for "Import Certificate and Private Key" has been expanded
beyond 16 characters.
➢ Default name when saving a CSR (Certificate Signing Request) is no longer
"certificate.cer".
➢ Under certain circumstances the certificate validity check performed during the IKE
portion of IPsec was done with the local printer time and not UTC time.
➢ If a Jetdirect 2900w in installed and two different wired networks are connected to
the printer (one on the JD 2900w and one on the Jetdirect Inside connection), then
it was possible (under certain circumstances) for the entire printer to become
unresponsive.
➢ This fix prevents the printer from resetting the connection during an intervention
event (paper out, paper jam, etc.) when printing using the LPD protocol.