Metrics
- CVSS v4.0 N/A
- CVSS v3.1 9.8 Critical
- CVSS v3.0 N/A
- CVSS v2 10.0 Critical
- KEV no
- EPSS 0.02486
- SSVC no
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.02486.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Xerox
Subscribe
|
Workcentre 3655
Subscribe
Workcentre 3655 Firmware
Subscribe
Workcentre 3655i
Subscribe
Workcentre 3655i Firmware
Subscribe
Workcentre 5865
Subscribe
Workcentre 5865 Firmware
Subscribe
Workcentre 5865i
Subscribe
Workcentre 5865i Firmware
Subscribe
Workcentre 5875
Subscribe
Workcentre 5875 Firmware
Subscribe
Workcentre 5875i
Subscribe
Workcentre 5875i Firmware
Subscribe
Workcentre 5890
Subscribe
Workcentre 5890 Firmware
Subscribe
Workcentre 5890i
Subscribe
Workcentre 5890i Firmware
Subscribe
Workcentre 5945
Subscribe
Workcentre 5945 Firmware
Subscribe
Workcentre 5945i
Subscribe
Workcentre 5945i Firmware
Subscribe
Workcentre 5955
Subscribe
Workcentre 5955 Firmware
Subscribe
Workcentre 5955i
Subscribe
Workcentre 5955i Firmware
Subscribe
Workcentre 6655
Subscribe
Workcentre 6655 Firmware
Subscribe
Workcentre 6655i
Subscribe
Workcentre 6655i Firmware
Subscribe
Workcentre 7200
Subscribe
Workcentre 7200 Firmware
Subscribe
Workcentre 7200i
Subscribe
Workcentre 7200i Firmware
Subscribe
Workcentre 7220
Subscribe
Workcentre 7220 Firmware
Subscribe
Workcentre 7225
Subscribe
Workcentre 7225 Firmware
Subscribe
Workcentre 7225i
Subscribe
Workcentre 7225i Firmware
Subscribe
Workcentre 7830
Subscribe
Workcentre 7830 Firmware
Subscribe
Workcentre 7835
Subscribe
Workcentre 7835 Firmware
Subscribe
Workcentre 7845
Subscribe
Workcentre 7845 Firmware
Subscribe
Workcentre 7855
Subscribe
Workcentre 7855 Firmware
Subscribe
Workcentre 7970
Subscribe
Workcentre 7970 Firmware
Subscribe
Workcentre 7970i
Subscribe
Workcentre 7970i Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-2050 | Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:47:34.938Z
Reserved: 2020-04-29T00:00:00
Link: CVE-2016-11061
No data.
Status : Modified
Published: 2020-04-29T22:15:11.810
Modified: 2024-11-21T02:45:24.550
Link: CVE-2016-11061
No data.
OpenCVE Enrichment
No data.
EUVD