Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Project Subscriptions

Vendors Products
Colorqube 8700 Subscribe
Colorqube 8700 Firmware Subscribe
Colorqube 8900 Subscribe
Colorqube 8900 Firmware Subscribe
Colorqube 9301 Subscribe
Colorqube 9301 Firmware Subscribe
Colorqube 9302 Subscribe
Colorqube 9302 Firmware Subscribe
Colorqube 9303 Subscribe
Colorqube 9303 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2602 Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Fixes

Solution

A fix for some models is available.


Workaround

There are no known workarounds for now available.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2024-08-04T22:32:02.151Z

Reserved: 2019-04-05T00:00:00

Link: CVE-2019-10880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-12T18:29:01.177

Modified: 2024-11-21T04:20:02.213

Link: CVE-2019-10880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses