VYPR

Vendor CVEs

Xerox

All CVEs

125 total · sorted by risk
  • CVE-2025-8356CriAug 8, 2025
    risk 0.65cvss 9.8epss 0.15

    In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.

  • CVE-2026-2251CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to…

  • CVE-2021-37354CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2019-10881CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.

  • CVE-2021-28672CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before…

  • CVE-2021-28671CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.03

    Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before…

  • CVE-2021-28673CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before…

  • CVE-2021-28668CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.

  • CVE-2016-11061CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute…

  • CVE-2019-13172CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.

  • CVE-2019-13171CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by…

  • CVE-2019-13169CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.

  • CVE-2019-13168CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on…

  • CVE-2019-13165CriMar 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the…

  • CVE-2013-6362CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

  • CVE-2019-17184CriOct 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.

  • CVE-2019-10880CriApr 12, 2019
    risk 0.64cvss 9.8epss 0.08

    Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

  • CVE-2018-20771CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.

  • CVE-2018-20770CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.

  • CVE-2018-20768CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.

  • CVE-2018-17172CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.02

    The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.

  • CVE-2021-28670CriMar 29, 2021
    risk 0.59cvss 9.1epss 0.01

    Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.

  • CVE-2020-9330HigFeb 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the…

  • CVE-2019-19832HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)

  • CVE-2018-20767HigFeb 10, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.

  • CVE-2024-47557HigOct 7, 2024
    risk 0.54cvss 8.3epss 0.01

    Pre-Auth RCE via Path Traversal

  • CVE-2024-47556HigOct 7, 2024
    risk 0.54cvss 8.3epss 0.01

    Pre-Auth RCE via Path Traversal

  • CVE-2024-47555HigOct 7, 2024
    risk 0.54cvss 8.3epss 0.00

    Missing Authentication - User & System Configuration

  • CVE-2019-18629HigMar 4, 2021
    risk 0.53cvss 8.1epss 0.01

    Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing…

  • CVE-2026-2252HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.  Please consider…

  • CVE-2025-8355HigAug 8, 2025
    risk 0.49cvss 7.5epss 0.07

    In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).

  • CVE-2024-12511HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

  • CVE-2024-55927HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.

  • CVE-2024-55926HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data

  • CVE-2024-55925HigJan 23, 2025
    risk 0.49cvss 7.5epss 0.00

    In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This…

  • CVE-2024-47559HigOct 7, 2024
    risk 0.49cvss 7.6epss 0.01

    Authenticated RCE via Path Traversal

  • CVE-2024-47558HigOct 7, 2024
    risk 0.49cvss 7.6epss 0.01

    Authenticated RCE via Path Traversal

  • CVE-2022-26572HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.

  • CVE-2022-23320HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.02

    XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

  • CVE-2022-23968HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing…

  • CVE-2021-28669HigMar 29, 2021
    risk 0.49cvss 7.5epss 0.01

    Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights.

  • CVE-2019-18630HigMar 4, 2021
    risk 0.49cvss 7.5epss 0.01

    On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic…

  • CVE-2020-36201HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.

  • CVE-2019-13166HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.

  • CVE-2018-20769HigFeb 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.

  • CVE-2024-6333HigOct 17, 2024
    risk 0.47cvss 7.2epss 0.01

    Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

  • CVE-2024-12510MedFeb 3, 2025
    risk 0.44cvss 6.7epss 0.01

    If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

  • CVE-2024-55930MedJan 23, 2025
    risk 0.44cvss 6.7epss 0.00

    Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files

  • CVE-2024-55931MedJan 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.  The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to…

  • CVE-2024-55928MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption

Page 1 of 3