Skip to main content

Faxploit Fax-based Malware Delivery Vulnerability

A group of researchers have disclosed a new attack methodology that exploits vulnerabilities in fax machines to gain access to a target network.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A group of researchers have disclosed a new attack methodology that exploits vulnerabilities in fax machines to gain access to a target network.

Threat details

The Check Point researchers claim they are able to execute files in the form of a fax on any fax machine that receives them. Fax machines transmit images by scanning the image, encoding the image data before sending it over a network to a recipient machine, which then decodes the data and reconstructs the original image. The researchers discovered that by encoding a specially crafted file within an image and faxing it to a recipient machine they were able to execute that file on that machine. When the recipient machine decodes the file it inadvertently executes it as well; this could allow a remote attacker to send malicious files to a target fax machine, where they would then be executed.

As of 2017, the NHS has less than 9000 fax machines present across the estate, with a large percentage of these being multi-function office printers.

For further information


Remediation steps

Type Step

Several vendors have already released firmware updates to address there vulnerabilities. Users should check with their relevant vendors and apply any available updates.

Organisations should also review their usage of fax machines and consider alternatives methods for sending files, such as:

  • Secure email services such as NHSMail 2.
  • Secure file transfer protocols and services such as SFTP.

If organisations wish to continue to use fax machines they should ensure the machines are properly segregated on the network and that their fax numbers are only made available to known users.


Last edited: 17 February 2020 12:43 pm