Lucene search

K

Xerox Security Vulnerabilities

cve
cve

CVE-2023-46327

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the...

5.9CVSS

5.6AI Score

0.001EPSS

2023-11-02 03:15 AM
37
cve
cve

CVE-2022-26572

Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive...

7.5CVSS

7.5AI Score

0.002EPSS

2022-04-04 07:15 PM
50
cve
cve

CVE-2022-23320

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the...

7.5CVSS

7.6AI Score

0.001EPSS

2022-02-07 11:15 AM
30
cve
cve

CVE-2022-45897

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those...

6.5CVSS

6.4AI Score

0.001EPSS

2023-01-31 12:15 AM
25
cve
cve

CVE-2012-0773

The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to...

7.5AI Score

0.015EPSS

2012-03-28 07:55 PM
125
cve
cve

CVE-2002-1834

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job...

7.1AI Score

0.003EPSS

2022-10-03 04:23 PM
21
cve
cve

CVE-2002-1835

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the...

7AI Score

0.006EPSS

2022-10-03 04:23 PM
16
cve
cve

CVE-2002-1836

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive...

7AI Score

0.003EPSS

2022-10-03 04:23 PM
23
cve
cve

CVE-2005-2202

Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown...

5.8AI Score

0.002EPSS

2022-10-03 04:22 PM
20
cve
cve

CVE-2005-2201

Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP...

6.7AI Score

0.005EPSS

2022-10-03 04:22 PM
22
cve
cve

CVE-2018-20768

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable...

9.8CVSS

9.6AI Score

0.003EPSS

2022-10-03 04:22 PM
28
cve
cve

CVE-2018-20769

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion...

7.5CVSS

8AI Score

0.002EPSS

2022-10-03 04:22 PM
32
cve
cve

CVE-2018-20767

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command...

8.8CVSS

9.2AI Score

0.002EPSS

2022-10-03 04:22 PM
21
cve
cve

CVE-2018-20770

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL...

9.8CVSS

9.7AI Score

0.001EPSS

2022-10-03 04:22 PM
22
cve
cve

CVE-2018-20771

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command...

9.8CVSS

9.7AI Score

0.004EPSS

2022-10-03 04:22 PM
20
cve
cve

CVE-2006-6469

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL...

7AI Score

0.001EPSS

2022-10-03 04:21 PM
21
cve
cve

CVE-2006-6467

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB...

7.3AI Score

0.001EPSS

2022-10-03 04:21 PM
17
cve
cve

CVE-2006-6470

The SNMP Agent in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 returns no error for a non-writable object, which has unknown impact and attack vectors. NOTE: due to the vagueness of the advisory, it is not clear whether this is.....

7AI Score

0.002EPSS

2022-10-03 04:21 PM
24
cve
cve

CVE-2006-6471

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file...

7.1AI Score

0.002EPSS

2022-10-03 04:21 PM
22
cve
cve

CVE-2006-6472

The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack...

7AI Score

0.002EPSS

2022-10-03 04:21 PM
33
cve
cve

CVE-2006-6468

Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed...

7AI Score

0.001EPSS

2022-10-03 04:21 PM
18
cve
cve

CVE-2006-6473

Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if...

7.2AI Score

0.002EPSS

2022-10-03 04:21 PM
20
cve
cve

CVE-2010-0548

Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox authorization or (2) read device configuration information...

6.8AI Score

0.003EPSS

2022-10-03 04:21 PM
23
cve
cve

CVE-2010-0549

Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized....

6.8AI Score

0.003EPSS

2022-10-03 04:21 PM
18
cve
cve

CVE-2021-37354

Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow...

9.8CVSS

9.6AI Score

0.002EPSS

2022-02-15 08:15 PM
62
cve
cve

CVE-2022-23321

A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version...

4.8CVSS

4.9AI Score

0.001EPSS

2022-02-10 07:15 PM
107
cve
cve

CVE-2022-23968

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as...

7.5CVSS

7.5AI Score

0.002EPSS

2022-01-26 06:15 AM
25
cve
cve

CVE-2019-10881

Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be...

9.8CVSS

9.4AI Score

0.002EPSS

2021-04-13 09:15 PM
33
5
cve
cve

CVE-2021-28672

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01.....

9.8CVSS

9.9AI Score

0.007EPSS

2021-03-29 09:15 PM
25
cve
cve

CVE-2021-28671

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01.....

9.8CVSS

9.6AI Score

0.004EPSS

2021-03-29 09:15 PM
22
cve
cve

CVE-2021-28668

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection...

9.8CVSS

9.8AI Score

0.001EPSS

2021-03-29 08:15 PM
23
cve
cve

CVE-2021-28673

Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before 33.61.23 and 33.59.01.....

9.8CVSS

9.7AI Score

0.003EPSS

2021-03-29 08:15 PM
26
cve
cve

CVE-2021-28669

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative...

7.5CVSS

7.5AI Score

0.001EPSS

2021-03-29 08:15 PM
14
cve
cve

CVE-2021-28670

Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the...

9.1CVSS

9AI Score

0.001EPSS

2021-03-29 06:15 PM
19
cve
cve

CVE-2021-20679

Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort...

7.5CVSS

7.4AI Score

0.002EPSS

2021-03-25 06:15 AM
73
cve
cve

CVE-2019-18630

On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information...

7.5CVSS

7.8AI Score

0.002EPSS

2021-03-04 11:15 PM
43
2
cve
cve

CVE-2019-18629

Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a...

8.1CVSS

8.1AI Score

0.002EPSS

2021-03-04 07:15 AM
55
5
cve
cve

CVE-2019-18628

Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow a user with administrative privileges to turn off data encryption on the device, thus leaving it open to potential cryptographic information...

4.9CVSS

5.8AI Score

0.001EPSS

2021-03-04 07:15 AM
52
4
cve
cve

CVE-2020-36201

An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856...

7.5CVSS

7.5AI Score

0.002EPSS

2021-01-26 06:15 PM
28
1
cve
cve

CVE-2020-26162

Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description...

6.1CVSS

6AI Score

0.001EPSS

2020-10-09 07:15 AM
41
cve
cve

CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the.....

9.8CVSS

9.7AI Score

0.002EPSS

2020-04-29 10:15 PM
23
cve
cve

CVE-2019-13171

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure...

9.8CVSS

9.7AI Score

0.005EPSS

2020-03-13 07:15 PM
59
cve
cve

CVE-2019-13172

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the...

9.8CVSS

9.8AI Score

0.005EPSS

2020-03-13 07:15 PM
42
cve
cve

CVE-2019-13170

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the...

6.5CVSS

6.4AI Score

0.001EPSS

2020-03-13 07:15 PM
43
cve
cve

CVE-2019-13165

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the...

9.8CVSS

9.8AI Score

0.004EPSS

2020-03-13 07:15 PM
71
cve
cve

CVE-2019-13166

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing...

7.5CVSS

7.5AI Score

0.002EPSS

2020-03-13 07:15 PM
34
cve
cve

CVE-2019-13167

Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted...

6.1CVSS

6.2AI Score

0.001EPSS

2020-03-13 07:15 PM
72
cve
cve

CVE-2019-13168

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the...

9.8CVSS

9.8AI Score

0.004EPSS

2020-03-13 07:15 PM
73
cve
cve

CVE-2019-13169

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the...

9.8CVSS

9.8AI Score

0.005EPSS

2020-03-13 07:15 PM
63
cve
cve

CVE-2020-9330

Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP....

8.8CVSS

8.7AI Score

0.001EPSS

2020-02-21 11:15 PM
107
Total number of security vulnerabilities115