10

CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.

Data is provided by the National Vulnerability Database (NVD)
XeroxWorkcentre 3655 Firmware Version < 073.060.086.15410
   XeroxWorkcentre 3655 Version-
XeroxWorkcentre 3655i Firmware Version < 073.060.086.15410
   XeroxWorkcentre 3655i Version-
XeroxWorkcentre 5865 Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5865 Version-
XeroxWorkcentre 5875 Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5875 Version-
XeroxWorkcentre 5890 Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5890 Version-
XeroxWorkcentre 5865i Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5865i Version-
XeroxWorkcentre 5875i Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5875i Version-
XeroxWorkcentre 5890i Firmware Version < 073.190.086.15410
   XeroxWorkcentre 5890i Version-
XeroxWorkcentre 5945 Firmware Version < 073.091.086.15410
   XeroxWorkcentre 5945 Version-
XeroxWorkcentre 5955 Firmware Version < 073.091.086.15410
   XeroxWorkcentre 5955 Version-
XeroxWorkcentre 5945i Firmware Version < 073.091.086.15410
   XeroxWorkcentre 5945i Version-
XeroxWorkcentre 5955i Firmware Version < 073.091.086.15410
   XeroxWorkcentre 5955i Version-
XeroxWorkcentre 6655 Firmware Version < 073.110.086.15410
   XeroxWorkcentre 6655 Version-
XeroxWorkcentre 6655i Firmware Version < 073.110.086.15410
   XeroxWorkcentre 6655i Version-
XeroxWorkcentre 7200 Firmware Version < 073.030.086.15410
   XeroxWorkcentre 7200 Version-
XeroxWorkcentre 7200i Firmware Version < 073.030.086.15410
   XeroxWorkcentre 7200i Version-
XeroxWorkcentre 7225i Firmware Version < 073.030.086.15410
   XeroxWorkcentre 7225i Version-
XeroxWorkcentre 7830 Firmware Version < 073.010.086.15410
   XeroxWorkcentre 7830 Version-
XeroxWorkcentre 7835 Firmware Version < 073.010.086.15410
   XeroxWorkcentre 7835 Version-
XeroxWorkcentre 7845 Firmware Version < 073.010.086.15410
   XeroxWorkcentre 7845 Version-
XeroxWorkcentre 7855 Firmware Version < 073.010.086.15410
   XeroxWorkcentre 7855 Version-
XeroxWorkcentre 7970 Firmware Version < 073.200.086.15410
   XeroxWorkcentre 7970 Version-
XeroxWorkcentre 7970i Firmware Version < 073.200.086.15410
   XeroxWorkcentre 7970i Version-
XeroxWorkcentre 7225 Firmware Version < 073.030.086.15410
   XeroxWorkcentre 7225 Version-
XeroxWorkcentre 7220 Firmware Version < 073.030.086.15410
   XeroxWorkcentre 7220 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.49% 0.847
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.