Description
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Published: 2019-04-12
Score: 9.8 Critical
EPSS: 5.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

A fix for some models is available.


Vendor Workaround

There are no known workarounds for now available.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-2602 Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
History

No history.

Subscriptions

Xerox Colorqube 8700 Colorqube 8700 Firmware Colorqube 8900 Colorqube 8900 Firmware Colorqube 9301 Colorqube 9301 Firmware Colorqube 9302 Colorqube 9302 Firmware Colorqube 9303 Colorqube 9303 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2024-08-04T22:32:02.151Z

Reserved: 2019-04-05T00:00:00.000Z

Link: CVE-2019-10880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-12T18:29:01.177

Modified: 2024-11-21T04:20:02.213

Link: CVE-2019-10880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses