8.8
CVE-2018-20767
- EPSS 1.69%
- Veröffentlicht 10.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:07
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Workcentre 3655i Firmware Version < 073.060.048.15000
Xerox ≫ Workcentre 3655 Firmware Version < 073.060.048.15000
Xerox ≫ Workcentre 5890i Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5865i Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5875i Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5845 Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5865 Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5875 Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5890 Firmware Version < 073.190.048.15000
Xerox ≫ Workcentre 5900 Firmware Version < 073.091.048.15000
Xerox ≫ Workcentre 5900i Firmware Version < 073.091.048.15000
Xerox ≫ Workcentre 6655 Firmware Version < 073.110.048.15000
Xerox ≫ Workcentre 6655i Firmware Version < 073.110.048.15000
Xerox ≫ Workcentre 7855 Firmware Version < 073.040.048.15000
Xerox ≫ Workcentre 7225 Firmware Version < 073.030.048.15000
Xerox ≫ Workcentre 7220 Firmware Version < 073.030.048.15000
Xerox ≫ Workcentre 7220i Firmware Version < 073.030.048.15000
Xerox ≫ Workcentre 7225i Firmware Version < 073.030.048.15000
Xerox ≫ Workcentre 7855i Firmware Version < 073.040.048.15000
Xerox ≫ Workcentre 7845i Firmware Version < 073.040.048.15000
Xerox ≫ Workcentre 7835i Firmware Version < 073.010.048.15000
Xerox ≫ Workcentre 7830i Firmware Version < 073.010.048.15000
Xerox ≫ Workcentre 7830 Firmware Version < 073.010.048.15000
Xerox ≫ Workcentre 7835 Firmware Version < 073.010.048.15000
Xerox ≫ Workcentre 7845 Firmware Version < 073.040.048.15000
Xerox ≫ Workcentre 7970 Firmware Version < 073.200.048.15000
Xerox ≫ Workcentre 7970i Firmware Version < 073.200.048.15000
Xerox ≫ Workcentre Ec7836 Firmware Version < 073.050.048.15000
Xerox ≫ Workcentre Ec7856 Firmware Version < 073.020.048.15000
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.69% | 0.814 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.