10

CVE-2019-10880

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Colorqube 8700 Firmware Version < 072.161.009.07200
   Xerox ≫ Colorqube 8700 Version -
Xerox ≫ Colorqube 8900 Firmware Version < 072.161.009.07200
   Xerox ≫ Colorqube 8900 Version -
Xerox ≫ Colorqube 9301 Firmware Version < 072.180.009.07200
   Xerox ≫ Colorqube 9301 Version -
Xerox ≫ Colorqube 9302 Firmware Version < 072.180.009.07200
   Xerox ≫ Colorqube 9302 Version -
Xerox ≫ Colorqube 9303 Firmware Version < 072.180.009.07200
   Xerox ≫ Colorqube 9303 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.47% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Airbus 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://airbus-seclab.github.io/
Not Applicable
https://securitydocs.business.xerox.com/wp-content/uploads/2019/04/cert_Security_Mini_Bulletin_XRX19C_for_CQ8700_CQ8900_CQ93xx.pdf
Vendor Advisory