Lucene search

K
cveMitreCVE-2006-5290
HistoryOct 13, 2006 - 8:07 p.m.

CVE-2006-5290

2006-10-1320:07:00
mitre
web.nvd.nist.gov
24
xerox
workcentre
workcentre pro
remote code execution
authentication bypass
webui
tcp/ip
cve-2006-5290

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.09

Percentile

94.7%

The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via “WebUI command injection on TCP/IP hostname.”

Affected configurations

Nvd
Node
xeroxworkcentre_232
OR
xeroxworkcentre_232pro
OR
xeroxworkcentre_238
OR
xeroxworkcentre_238pro
OR
xeroxworkcentre_245
OR
xeroxworkcentre_245pro
OR
xeroxworkcentre_255
OR
xeroxworkcentre_255pro
OR
xeroxworkcentre_265
OR
xeroxworkcentre_265pro
OR
xeroxworkcentre_275
OR
xeroxworkcentre_275pro
VendorProductVersionCPE
xeroxworkcentre_232*cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*
xeroxworkcentre_232*cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*
xeroxworkcentre_238*cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*
xeroxworkcentre_238*cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*
xeroxworkcentre_245*cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*
xeroxworkcentre_245*cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*
xeroxworkcentre_255*cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*
xeroxworkcentre_255*cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*
xeroxworkcentre_265*cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*
xeroxworkcentre_265*cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.09

Percentile

94.7%

Related for CVE-2006-5290