{"product_id":10197,"v_id":10197,"product_name":"Lexmark X642e (firmware revision LC2.MB.P237) and X644e (firmware revision LC2.MC.P239b) Multifunction Printers (MFPs). ","certification_status":"Not Certified","certification_date":"2007-09-21T00:09:00Z","tech_type":"Miscellaneous, Multi Function Device","vendor_id":{"name":"Lexmark International, Inc.","website":"http://www.lexmark.com"},"vendor_poc":"Sean Gibbons","vendor_phone":"859-232-2000","vendor_email":"gibbonss@lexmark.com","assigned_lab":{"cctl_name":"COACT, Inc. Labs"},"product_description":"<p>The Lexmark MFP is a multi-functional printer system with scanning, fax, and networked capabilities.&nbsp; Its capabilities extend to walk-up scanning and copying, scanning to fax, scanning to email, and servicing print jobs through the network. The MFP also enables users to insert a USB Drive, which can be used as the source for print operations or the destination for scan operations.&nbsp; The MFP includes print, fax and scan functionality with an integrated touch-sensitive operator panel.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that the Lexmark X642e (firmware revision LC2.MB.P237) and X644e (firmware revision LC2.MC.P239b) Multifunction Printers (MFPs) meet the security requirements contained in the Security Target.</p>\r\n<p><br />\r\nThe criteria against which the Lexmark X642e (firmware revision LC2.MB.P237) and X644e (firmware revision LC2.MC.P239b) Multifunction Printers (MFPs) were judged are described in the Common Criteria for Information Technology Security Evaluation, Version 2.3. The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 2.3. The COACT, Inc. CAFE Lab determined that the evaluation assurance level (EAL) for the Lexmark X642e (firmware revision LC2.MB.P237) and X644e (firmware revision LC2.MC.P239b) Multifunction Printers (MFPs) is EAL 2. The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.</p>\r\n<p><br />\r\nA Validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by the COACT, Inc. CAFE Lab. The evaluation was completed in June 2007. Results of the evaluation and associated validation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report.</p>","environmental_strengths":"<p>The TOE&rsquo;s Security Functions are summarized as follows:</p>\r\n<p><strong><br />\r\nFax Communications Control</strong><br />\r\nThe Fax Communications Control security function assures that the information on the TOE, and the information on the network to which the TOE is attached, is not exposed through the phone line that provides connectivity for the analog fax function.&nbsp; Control of the fax functionality is incorporated directly into the TOE&rsquo;s firmware. There is no mechanism by which telnet, FTP, or other network protocols can be sent or received over the analog fax line. <br />\r\n<br />\r\n<strong>User Authentication</strong><br />\r\nThe TOE&rsquo;s display interface allows access to the print-from USB operation and the following types of scan-based operations to touch screen users: scan-to-fax, scan-to-copy, scan-to-USB, and scan-to-email.&nbsp; Each of these operations is restricted with the User Authentication function, which requires the touch screen user&rsquo;s credentials to be submitted and validated before the TOE gives the touch screen user access to the operation.&nbsp;&nbsp; No identification or authentication is performed for network print users or inbound fax users.&nbsp; <br />\r\n<br />\r\n<strong>Device Configuration Protection</strong><br />\r\nThe configurable settings that control the behaviour of the MFP can only be modified after authentication with the TOE&rsquo;s administrative credentials. In addition, management of the MFP occurs primarily via remote access utilizing HTTPS.&nbsp; These sessions provide protection against disclosure and modification via SSL v2 and v3 and TLS v1.<br />\r\n<strong>&nbsp;<br />\r\nTSF Self Protection</strong><br />\r\nThe MFP protects itself by ensuring that security functions may not be bypassed by activities within the TSC and by implementing security domains that protect it from interference and tampering by untrusted subjects within the TSC.</p>","features":[]}