Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-11061


Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.


Published

2020-04-29T22:15:11.810

Last Modified

2024-11-21T02:45:24.550

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System xerox workcentre_3655_firmware < 073.060.086.15410 Yes
Hardware xerox workcentre_3655 - No
Operating System xerox workcentre_3655i_firmware < 073.060.086.15410 Yes
Hardware xerox workcentre_3655i - No
Operating System xerox workcentre_5865_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5865 - No
Operating System xerox workcentre_5875_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5875 - No
Operating System xerox workcentre_5890_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5890 - No
Operating System xerox workcentre_5865i_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5865i - No
Operating System xerox workcentre_5875i_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5875i - No
Operating System xerox workcentre_5890i_firmware < 073.190.086.15410 Yes
Hardware xerox workcentre_5890i - No
Operating System xerox workcentre_5945_firmware < 073.091.086.15410 Yes
Hardware xerox workcentre_5945 - No
Operating System xerox workcentre_5955_firmware < 073.091.086.15410 Yes
Hardware xerox workcentre_5955 - No
Operating System xerox workcentre_5945i_firmware < 073.091.086.15410 Yes
Hardware xerox workcentre_5945i - No
Operating System xerox workcentre_5955i_firmware < 073.091.086.15410 Yes
Hardware xerox workcentre_5955i - No
Operating System xerox workcentre_6655_firmware < 073.110.086.15410 Yes
Hardware xerox workcentre_6655 - No
Operating System xerox workcentre_6655i_firmware < 073.110.086.15410 Yes
Hardware xerox workcentre_6655i - No
Operating System xerox workcentre_7200_firmware < 073.030.086.15410 Yes
Hardware xerox workcentre_7200 - No
Operating System xerox workcentre_7200i_firmware < 073.030.086.15410 Yes
Hardware xerox workcentre_7200i - No
Operating System xerox workcentre_7225i_firmware < 073.030.086.15410 Yes
Hardware xerox workcentre_7225i - No
Operating System xerox workcentre_7830_firmware < 073.010.086.15410 Yes
Hardware xerox workcentre_7830 - No
Operating System xerox workcentre_7835_firmware < 073.010.086.15410 Yes
Hardware xerox workcentre_7835 - No
Operating System xerox workcentre_7845_firmware < 073.010.086.15410 Yes
Hardware xerox workcentre_7845 - No
Operating System xerox workcentre_7855_firmware < 073.010.086.15410 Yes
Hardware xerox workcentre_7855 - No
Operating System xerox workcentre_7970_firmware < 073.200.086.15410 Yes
Hardware xerox workcentre_7970 - No
Operating System xerox workcentre_7970i_firmware < 073.200.086.15410 Yes
Hardware xerox workcentre_7970i - No
Operating System xerox workcentre_7225_firmware < 073.030.086.15410 Yes
Hardware xerox workcentre_7225 - No
Operating System xerox workcentre_7220_firmware < 073.030.086.15410 Yes
Hardware xerox workcentre_7220 - No

References