Description
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
No analysis available yet.
Remediation
Vendor Solution
A fix for some models is available.
Vendor Workaround
There are no known workarounds for now available.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2602 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary. |
References
History
No history.
Subscriptions
Xerox
Subscribe
Colorqube 8700
Subscribe
Colorqube 8700 Firmware
Subscribe
Colorqube 8900
Subscribe
Colorqube 8900 Firmware
Subscribe
Colorqube 9301
Subscribe
Colorqube 9301 Firmware
Subscribe
Colorqube 9302
Subscribe
Colorqube 9302 Firmware
Subscribe
Colorqube 9303
Subscribe
Colorqube 9303 Firmware
Subscribe
Status: PUBLISHED
Assigner: airbus
Published:
Updated: 2024-08-04T22:32:02.151Z
Reserved: 2019-04-05T00:00:00.000Z
Link: CVE-2019-10880
No data.
Status : Modified
Published: 2019-04-12T18:29:01.177
Modified: 2024-11-21T04:20:02.213
Link: CVE-2019-10880
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD