Lucene search

K
cve[email protected]CVE-2019-10880
HistoryApr 12, 2019 - 6:29 p.m.

CVE-2019-10880

2019-04-1218:29:01
CWE-78
web.nvd.nist.gov
41
xerox
vulnerability
remote command execution
linux
os command injection
http interface
authentication

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.5%

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the “nobody” user through a crafted “HTTP” request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Affected configurations

NVD
Node
xeroxcolorqube_8700Match-
AND
xeroxcolorqube_8700_firmwareRange<072.161.009.07200
Node
xeroxcolorqube_8900Match-
AND
xeroxcolorqube_8900_firmwareRange<072.161.009.07200
Node
xeroxcolorqube_9301Match-
AND
xeroxcolorqube_9301_firmwareRange<072.180.009.07200
Node
xeroxcolorqube_9302Match-
AND
xeroxcolorqube_9302_firmwareRange<072.180.009.07200
Node
xeroxcolorqube_9303Match-
AND
xeroxcolorqube_9303_firmwareRange<072.180.009.07200

CNA Affected

[
  {
    "product": "AltaLink B8045/B8055/B8065/B8075/B8090",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "101.008.008.27400",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "AltaLink C8030/C8035/C8045/C8055/C8070",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "101.001.008.27400",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 3655",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.060.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 5845/5855/5865/5875/5890",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.190.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 5945/5955",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.091.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 6655",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.110.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 7220/7225",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.030.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 7830/7835/7845/7855",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.010.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 7970",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.200.075.34540",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre EC7836/EC7856",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "073.020.167.17200",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ColorQube 9301/9302/9303",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThan": "072.xxx.009.07200",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ColorQube 8700/8900",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThan": "072.xxx.009.07200",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 6400",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "061.070.100.24201",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Phaser 6700",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "081.140.103.22600",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Phaser 7800",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "081.150.103.05600",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 5735/5740/5745/5755/5765/5775/5790",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "061.132.221.21403",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 7525/7530/7535/7545/7556",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "061.121.224.18803",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "WorkCentre 7755/7765/7775",
    "vendor": "XEROX",
    "versions": [
      {
        "lessThanOrEqual": "061.090.220.19700",
        "status": "unknown",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.5%

Related for CVE-2019-10880