8.1
CVE-2019-18629
- EPSS 0.45%
- Veröffentlicht 04.03.2021 07:15:15
- Zuletzt bearbeitet 21.11.2024 04:33:24
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a compromised private key.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Altalink B8045 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8055 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8065 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8075 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8090 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink C8030 Firmware Version < 101.001.099.28200
Xerox ≫ Altalink C8035 Firmware Version < 101.001.099.28200
Xerox ≫ Altalink C8045 Firmware Version < 101.002.099.28200
Xerox ≫ Altalink C8055 Firmware Version < 101.002.099.28200
Xerox ≫ Altalink C8070 Firmware Version < 101.003.099.28200
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.608 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|