{"product_id":10135,"v_id":10135,"product_name":"Xerox WorkCentre/WorkCenter Pro 232/238/245/255/265/275 Multifunction Systems","certification_status":"Not Certified","certification_date":"2006-04-06T00:04:00Z","tech_type":"Miscellaneous","vendor_id":{"name":"Xerox Corporation","website":"www.xerox.com"},"vendor_poc":"Larry Kovnat","vendor_phone":"585.427.1732","vendor_email":"larry.kovnat@xerox.com","assigned_lab":{"cctl_name":"DXC.technology"},"product_description":"<p>The TOE is a multi-function device (hereafter referred to as a MFD) that copies, prints, scans to e-mail, scans to a network repository, and analog faxes from either the platen or the print driver (the latter referred to as LanFax). The MFD contains an internal hard disk drive (referred to as Network Controller HDD). Standard security functions include SSL, IPSec, SNMPv3, a host-based firewall, and an internal audit log. Users may be authenticated to the network or locally at the device. The evaluated configuration also includes the Image Overwrite Security package, a consumer option. The Image Overwrite Security package causes any temporary image files created during a print, network scan, scan-to-email, or LanFax job to be erased from the internal hard disk drive when those files are no longer needed or on demand at the discretion of the system administrator. [Copy and analog fax jobs initiated from the platen do not create files on the Network Controller HDD so no overwrite is needed for these job types.]</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the product meets the security requirements contained in the Security Target. The criteria against which the <em>Xerox WorkCentre&reg;/WorkCentre&reg; Pro 232/238/245/255/265/275 Multifunction Systems </em>were evaluated as described in the <em>Common Criteria for Information Technology Security Evaluation, Version 2.2</em>. The evaluation methodology used by the evaluation team to conduct the evaluation is the <em>Common Methodology for Information Technology Security Evaluation, Version 2.2</em>. Computer Sciences Corporation determined that the evaluation assurance level (EAL) for the product is EAL 2 Augmented with ALC_FLR.2. The product, when configured and installed according to supplied guidance, satisfies all of the security functional requirements stated in the Security Target. A validator, on behalf of the CCEVS Validation Body, monitored the evaluation carried out by Computer Sciences Corporation. The evaluation was completed in March 2006. Results of the evaluation can be found in the <em>Evaluation Technical Report for a Target of Evaluation for Xerox WorkCentre&reg;/WorkCentre&reg; Pro 232/238/245/255/265/275 Multifunction Systems </em>prepared by Computer Sciences Corporation.</p>","environmental_strengths":"<p>The TOE provides the following security features:</p>\r\n<p><strong>Communications Security:</strong> The WorkCentre&reg;/WorkCentre&reg; Pro models provide secure communications over the SSL, IPSec, and SNMPv3 protocols. Remote management of the device is secured from the Web User Interface using HTTPS/SSL. Alternatively secure remote management is provided using a manager that supports SNMPv3. Secure scanning to a repository is provided using HTTPS/SSL. Secure printing is provided by using IPSec. </p>\r\n<p><strong>Information Flow Control:</strong> The WorkCentre&reg;/WorkCentre&reg; Pro models implement a static, host-based firewall that limits network access to the device. The system administrator can control access based on source IP address and/or destination network protocol/port. Access rules can be administered via a secure interface provided by the Web UI. </p>\r\n<p><strong>Auditing:</strong>The WorkCentre&reg;/WorkCentre&reg; Pro models generate logs that track events/actions (e.g. print/scan/LanFax job submission) to logged in users, and each log entry contains a timestamp. The audit logs are only available to system administrators and can be securely downloaded via the Web interface for viewing and analysis. </p>\r\n<p><strong>Authentication:</strong> The WorkCentre&reg;/WorkCentre&reg; Promodels can authenticate users to a remote network authentication server. Supported authentication services include Kerberos (Solaris), Kerberos (Windows 2000), NDS (Novell 4.x, 5.x), and SMB (Windows NT.4x/2000). The system prevents unauthorized use of the installed network options (network scanning, scan-to-email, and LanFax) unless the user is properly authenticated. To access a network service, the user is required to provide a user name and password which is then validated by the remote authentication server. </p>\r\n<p>To authenticate the system administrator, the WorkCentre&reg;/WorkCentre&reg; Promodels utilize a simple authentication function accessible through the front panel or web interface. The system administrator must authenticate by entering an 8 to 12 digit PIN prior to being granted access to the tools menu and system administrator functions. The system administrator must change the default PIN after installation is complete. While the system administrator is entering the PIN number, the TOE displays a &lsquo;*&rsquo; character for each digit entered to hide the value entered. The authentication mechanism has a PIN space of 12**3 to 12**12. </p>\r\n<p>The Web user interface also requires the user to enter a PIN and enter &ldquo;admin&rdquo; into the username field. The username prompt provided by the web server is not used, but is provided for historical reasons. The only valid string is &ldquo;admin&rdquo;, which is hard coded into the web server and cannot be changed. Additional users cannot be added. The TOE does not associate user attribute or privileges based on username. </p>\r\n<p><strong>Image Overwrite:</strong> The WorkCentre&reg;/WorkCentre&reg; Promodels implement an image overwrite security function (Immediate Image Overwrite (IIO)) that causes temporary image files created during a print, network scan, scan-to-email, or LanFax job to be overwritten using a three pass overwrite procedure as described in DOD 5800.28-M. The function can also be manually invoked by the system administrator using the &ldquo;On-Demand&rdquo; Image Overwrite (ODIO) function. [Copy and analog fax jobs initiated from the platen do not create files on the Network Controller HDD so no overwrite is needed for these job types.] </p>\r\n<p>Once invoked, ODIO cancels all copy, print, network scan, scan-to-email, LanFax, or analog fax, jobs, halts the printer interface, and overwrites the contents of the sectors used for temporary image files on the internal hard disk drive. The entire machine then reboots. If the System Administrator attempts to activate diagnostics mode while ODIO is in progress, the request will be queued until the ODIO completes and then the system will enter diagnostic mode.<br />\r\n<strong>Security Management:</strong> The WorkCentre&reg;/WorkCentre&reg; Promodels utilize the front panel software module security mechanisms to allow only authenticated system administrators the capability to invoke or abort the ODIO function, enable or disable the IIO function, enable or disable embedded fax, and change the system administrator PIN. Additionally, the TOE utilizes the web server authentication mechanism to allow only authenticated system administrators the capability to configure SSL, IPSec, and/or SNMPv3, to manage IP filtering rules, to download the audit log, to configure network authentication, or to manually invoke &ldquo;On Demand&rdquo; Image Overwrite. </p>\r\n<p>The WorkCentre&reg;/WorkCentre&reg; Promodels restrict the ability to manage administrative functions to the system administrator. </p>\r\n<p><strong>Fax-Network Separation:</strong> The WorkCentre&reg;/WorkCentre&reg; Promodels have an architecture that provides separation between the optional FAX processing board and the network controller. This architecture ensures that a malicious user cannot access network resources from the telephone line via the system&rsquo;s optional FAX modem. </p>","features":[]}