7.8
CVE-2006-6430
- EPSS 1.55%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:07
- Erkennungen
Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Workcentre 232 Edition pro
Xerox ≫ Workcentre 238 Edition pro
Xerox ≫ Workcentre 245 Edition pro
Xerox ≫ Workcentre 255 Edition pro
Xerox ≫ Workcentre 265 Edition pro
Xerox ≫ Workcentre 275 Edition pro
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.55% | 0.72 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:C/I:N/A:N
|
http://secunia.com/advisories/23265
http://www.securityfocus.com/bid/21365
http://www.vupen.com/english/advisories/2006/4791
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_006_v1b.pdf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30679