Lucene search

K
cveMitreCVE-2006-6427
HistoryDec 10, 2006 - 11:28 a.m.

CVE-2006-6427

2006-12-1011:28:00
CWE-78
mitre
web.nvd.nist.gov
20
xerox
workcentre
remote command injection
cve-2006-6427
security vulnerability
nvd
tcp/ip
microsoft networking

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.09

Percentile

94.7%

The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving “command injection” in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.

Affected configurations

Nvd
Node
xeroxworkcentreMatch12.060.17.000
OR
xeroxworkcentreMatch12.060.17.000pro
OR
xeroxworkcentreMatch13.060.17.000
OR
xeroxworkcentreMatch13.060.17.000pro
OR
xeroxworkcentreMatch14.060.17.000
OR
xeroxworkcentreMatch14.060.17.000pro
VendorProductVersionCPE
xeroxworkcentre12.060.17.000cpe:2.3:h:xerox:workcentre:12.060.17.000:*:*:*:*:*:*:*
xeroxworkcentre12.060.17.000cpe:2.3:h:xerox:workcentre:12.060.17.000:*:pro:*:*:*:*:*
xeroxworkcentre13.060.17.000cpe:2.3:h:xerox:workcentre:13.060.17.000:*:*:*:*:*:*:*
xeroxworkcentre13.060.17.000cpe:2.3:h:xerox:workcentre:13.060.17.000:*:pro:*:*:*:*:*
xeroxworkcentre14.060.17.000cpe:2.3:h:xerox:workcentre:14.060.17.000:*:*:*:*:*:*:*
xeroxworkcentre14.060.17.000cpe:2.3:h:xerox:workcentre:14.060.17.000:*:pro:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.09

Percentile

94.7%

Related for CVE-2006-6427