8.1
CVE-2019-18629
- EPSS 0.45%
- Published 04.03.2021 07:15:15
- Last modified 21.11.2024 04:33:24
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a compromised private key.
Data is provided by the National Vulnerability Database (NVD)
Xerox ≫ Altalink B8045 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8055 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8065 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8075 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink B8090 Firmware Version < 101.008.099.28200
Xerox ≫ Altalink C8030 Firmware Version < 101.001.099.28200
Xerox ≫ Altalink C8035 Firmware Version < 101.001.099.28200
Xerox ≫ Altalink C8045 Firmware Version < 101.002.099.28200
Xerox ≫ Altalink C8055 Firmware Version < 101.002.099.28200
Xerox ≫ Altalink C8070 Firmware Version < 101.003.099.28200
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.608 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|