Vendor CVEs
Xerox
All CVEs
125 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8356 | Cri | 0.65 | 9.8 | 0.15 | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system. | ||
| CVE-2026-2251 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2026 | Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to… | ||
| CVE-2021-37354 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2022 | Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||
| CVE-2019-10881 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2021 | Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled. | ||
| CVE-2021-28672 | Cri | 0.64 | 9.8 | 0.02 | Mar 29, 2021 | Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before… | ||
| CVE-2021-28671 | Cri | 0.64 | 9.8 | 0.03 | Mar 29, 2021 | Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before… | ||
| CVE-2021-28673 | Cri | 0.64 | 9.8 | 0.02 | Mar 29, 2021 | Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before… | ||
| CVE-2021-28668 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2021 | Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities. | ||
| CVE-2016-11061 | Cri | 0.64 | 9.8 | 0.02 | Apr 29, 2020 | Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute… | ||
| CVE-2019-13172 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device. | ||
| CVE-2019-13171 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by… | ||
| CVE-2019-13169 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device. | ||
| CVE-2019-13168 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on… | ||
| CVE-2019-13165 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the… | ||
| CVE-2013-6362 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2020 | Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts. | ||
| CVE-2019-17184 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2019 | Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges. | ||
| CVE-2019-10880 | Cri | 0.64 | 9.8 | 0.08 | Apr 12, 2019 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary. | ||
| CVE-2018-20771 | Cri | 0.64 | 9.8 | 0.03 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution. | ||
| CVE-2018-20770 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection. | ||
| CVE-2018-20768 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file. | ||
| CVE-2018-17172 | Cri | 0.64 | 9.8 | 0.02 | Jan 3, 2019 | The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection. | ||
| CVE-2021-28670 | Cri | 0.59 | 9.1 | 0.01 | Mar 29, 2021 | Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk. | ||
| CVE-2020-9330 | Hig | 0.57 | 8.8 | 0.01 | Feb 21, 2020 | Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the… | ||
| CVE-2019-19832 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2019 | Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.) | ||
| CVE-2018-20767 | Hig | 0.57 | 8.8 | 0.02 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution. | ||
| CVE-2024-47557 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-47556 | Hig | 0.54 | 8.3 | 0.01 | Oct 7, 2024 | Pre-Auth RCE via Path Traversal | ||
| CVE-2024-47555 | Hig | 0.54 | 8.3 | 0.00 | Oct 7, 2024 | Missing Authentication - User & System Configuration | ||
| CVE-2019-18629 | Hig | 0.53 | 8.1 | 0.01 | Mar 4, 2021 | Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing… | ||
| CVE-2026-2252 | Hig | 0.49 | 7.5 | 0.00 | Feb 27, 2026 | An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider… | ||
| CVE-2025-8355 | Hig | 0.49 | 7.5 | 0.07 | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF). | ||
| CVE-2024-12511 | Hig | 0.49 | 7.6 | 0.01 | Feb 3, 2025 | With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. | ||
| CVE-2024-55927 | Hig | 0.49 | 7.6 | 0.00 | Jan 23, 2025 | A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions. | ||
| CVE-2024-55926 | Hig | 0.49 | 7.6 | 0.00 | Jan 23, 2025 | A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data | ||
| CVE-2024-55925 | Hig | 0.49 | 7.5 | 0.00 | Jan 23, 2025 | In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This… | ||
| CVE-2024-47559 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2024-47558 | Hig | 0.49 | 7.6 | 0.01 | Oct 7, 2024 | Authenticated RCE via Path Traversal | ||
| CVE-2022-26572 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2022 | Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information. | ||
| CVE-2022-23320 | Hig | 0.49 | 7.5 | 0.02 | Feb 7, 2022 | XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database. | ||
| CVE-2022-23968 | Hig | 0.49 | 7.5 | 0.02 | Jan 26, 2022 | Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing… | ||
| CVE-2021-28669 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2021 | Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights. | ||
| CVE-2019-18630 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2021 | On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic… | ||
| CVE-2020-36201 | Hig | 0.49 | 7.5 | 0.01 | Jan 26, 2021 | An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices. | ||
| CVE-2019-13166 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks. | ||
| CVE-2018-20769 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability. | ||
| CVE-2024-6333 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2024 | Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. | ||
| CVE-2024-12510 | Med | 0.44 | 6.7 | 0.01 | Feb 3, 2025 | If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup. | ||
| CVE-2024-55930 | Med | 0.44 | 6.7 | 0.00 | Jan 23, 2025 | Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files | ||
| CVE-2024-55931 | Med | 0.42 | 6.5 | 0.00 | Jan 27, 2025 | Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to… | ||
| CVE-2024-55928 | Med | 0.42 | 6.5 | 0.00 | Jan 23, 2025 | Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption |
- risk 0.65cvss 9.8epss 0.15
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
- risk 0.64cvss 9.8epss 0.00
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to…
- risk 0.64cvss 9.8epss 0.01
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
- risk 0.64cvss 9.8epss 0.01
Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.
- risk 0.64cvss 9.8epss 0.02
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before…
- risk 0.64cvss 9.8epss 0.03
Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before…
- risk 0.64cvss 9.8epss 0.02
Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610 before 32.61.23 and 32.59.01 (Bridge), B605/B615 before…
- risk 0.64cvss 9.8epss 0.01
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.
- risk 0.64cvss 9.8epss 0.02
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute…
- risk 0.64cvss 9.8epss 0.03
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.03
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by…
- risk 0.64cvss 9.8epss 0.03
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.03
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on…
- risk 0.64cvss 9.8epss 0.03
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the…
- risk 0.64cvss 9.8epss 0.01
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
- risk 0.64cvss 9.8epss 0.02
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
- risk 0.64cvss 9.8epss 0.08
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
- risk 0.64cvss 9.8epss 0.02
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.
- risk 0.59cvss 9.1epss 0.01
Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.
- risk 0.57cvss 8.8epss 0.01
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the…
- risk 0.57cvss 8.8epss 0.01
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
- risk 0.57cvss 8.8epss 0.02
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.01
Pre-Auth RCE via Path Traversal
- risk 0.54cvss 8.3epss 0.00
Missing Authentication - User & System Configuration
- risk 0.53cvss 8.1epss 0.01
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing…
- risk 0.49cvss 7.5epss 0.00
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider…
- risk 0.49cvss 7.5epss 0.07
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal URLs, this results in a Server-Side Request Forgery (SSRF).
- risk 0.49cvss 7.6epss 0.01
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
- risk 0.49cvss 7.6epss 0.00
A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.
- risk 0.49cvss 7.6epss 0.00
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
- risk 0.49cvss 7.5epss 0.00
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This…
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.6epss 0.01
Authenticated RCE via Path Traversal
- risk 0.49cvss 7.5epss 0.01
Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.
- risk 0.49cvss 7.5epss 0.02
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
- risk 0.49cvss 7.5epss 0.02
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing…
- risk 0.49cvss 7.5epss 0.01
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights.
- risk 0.49cvss 7.5epss 0.01
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
- risk 0.49cvss 7.5epss 0.01
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
- risk 0.47cvss 7.2epss 0.01
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
- risk 0.44cvss 6.7epss 0.01
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
- risk 0.44cvss 6.7epss 0.00
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
- risk 0.42cvss 6.5epss 0.00
Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to…
- risk 0.42cvss 6.5epss 0.00
Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption
Page 1 of 3