7.5

CVE-2018-20769

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.

Data is provided by the National Vulnerability Database (NVD)
XeroxWorkcentre 3655i Firmware Version < 073.060.048.15000
   XeroxWorkcentre 3655i Version-
XeroxWorkcentre 3655 Firmware Version < 073.060.048.15000
   XeroxWorkcentre 3655 Version-
XeroxWorkcentre 5890i Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5890i Version-
XeroxWorkcentre 5865i Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5865i Version-
XeroxWorkcentre 5875i Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5875i Version-
XeroxWorkcentre 5845 Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5845 Version-
XeroxWorkcentre 5865 Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5865 Version-
XeroxWorkcentre 5875 Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5875 Version-
XeroxWorkcentre 5890 Firmware Version < 073.190.048.15000
   XeroxWorkcentre 5890 Version-
XeroxWorkcentre 5900 Firmware Version < 073.091.048.15000
   XeroxWorkcentre 5900 Version-
XeroxWorkcentre 5900i Firmware Version < 073.091.048.15000
   XeroxWorkcentre 5900i Version-
XeroxWorkcentre 6655 Firmware Version < 073.110.048.15000
   XeroxWorkcentre 6655 Version-
XeroxWorkcentre 6655i Firmware Version < 073.110.048.15000
   XeroxWorkcentre 6655i Version-
XeroxWorkcentre 7855 Firmware Version < 073.040.048.15000
   XeroxWorkcentre 7855 Version-
XeroxWorkcentre 7225 Firmware Version < 073.030.048.15000
   XeroxWorkcentre 7225 Version-
XeroxWorkcentre 7220 Firmware Version < 073.030.048.15000
   XeroxWorkcentre 7220 Version-
XeroxWorkcentre 7220i Firmware Version < 073.030.048.15000
   XeroxWorkcentre 7220i Version-
XeroxWorkcentre 7225i Firmware Version < 073.030.048.15000
   XeroxWorkcentre 7225i Version-
XeroxWorkcentre 7855i Firmware Version < 073.040.048.15000
   XeroxWorkcentre 7855i Version-
XeroxWorkcentre 7845i Firmware Version < 073.040.048.15000
   XeroxWorkcentre 7845i Version-
XeroxWorkcentre 7835i Firmware Version < 073.010.048.15000
   XeroxWorkcentre 7835i Version-
XeroxWorkcentre 7830i Firmware Version < 073.010.048.15000
   XeroxWorkcentre 7830i Version-
XeroxWorkcentre 7830 Firmware Version < 073.010.048.15000
   XeroxWorkcentre 7830 Version-
XeroxWorkcentre 7835 Firmware Version < 073.010.048.15000
   XeroxWorkcentre 7835 Version-
XeroxWorkcentre 7845 Firmware Version < 073.040.048.15000
   XeroxWorkcentre 7845 Version-
XeroxWorkcentre 7970 Firmware Version < 073.200.048.15000
   XeroxWorkcentre 7970 Version-
XeroxWorkcentre 7970i Firmware Version < 073.200.048.15000
   XeroxWorkcentre 7970i Version-
XeroxWorkcentre Ec7836 Firmware Version < 073.050.048.15000
   XeroxWorkcentre Ec7836 Version-
XeroxWorkcentre Ec7856 Firmware Version < 073.020.048.15000
   XeroxWorkcentre Ec7856 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.38% 0.565
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.