Description
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."
Published: 2022-01-26
Score: 7.5 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-28884 Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."
History

No history.

Subscriptions

Xerox Versalink B400 Versalink B405 Versalink B600 Versalink B610 Versalink B7025 Versalink B7030 Versalink B7035 Versalink C400 Versalink C405 Versalink C500 Versalink C505 Versalink C600 Versalink C605 Versalink C7000 Versalink C7020 Versalink C7025 Versalink C7030 Versalink C8000 Versalink C8000w Versalink C9000 Versalink Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T03:59:23.128Z

Reserved: 2022-01-26T00:00:00.000Z

Link: CVE-2022-23968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-26T06:15:06.843

Modified: 2024-11-21T06:49:32.480

Link: CVE-2022-23968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses