7.6

CVE-2024-12511

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorXerox
Product Versalink B400
Default Statusunknown
Version < 37.82.53
Version 0
Status affected
VendorXerox
Product Versalink B405
Default Statusunknown
Version < 38.82.53
Version 0
Status affected
VendorXerox
Product Versalink C400
Default Statusunknown
Version < 67.82.53
Version 0
Status affected
VendorXerox
Product Versalink C405
Default Statusunknown
Version < 68.82.53
Version 0
Status affected
VendorXerox
Product Versalink B600/B610
Default Statusunknown
Version < 32.82.53
Version 0
Status affected
VendorXerox
Product Versalink B605/B615
Default Statusunknown
Version < 33.82.53
Version 0
Status affected
VendorXerox
Product Versalink C500/C600
Default Statusunknown
Version < 61.82.53
Version 0
Status affected
VendorXerox
Product Versalink C505/C605
Default Statusunknown
Version < 62.82.53
Version 0
Status affected
VendorXerox
Product Versalink C7000
Default Statusunknown
Version < 56.75.53
Version 0
Status affected
VendorXerox
Product Versalink C7020/C7025/C7030
Default Statusunknown
Version < 57.75.53
Version 0
Status affected
VendorXerox
Product Versalink B7025/B7030/B7035
Default Statusunknown
Version < 58.75.53
Version 0
Status affected
VendorXerox
Product Versalink B7125/B7130/B7135
Default Statusunknown
Version < 59.24.53
Version 0
Status affected
VendorXerox
Product Versalink C7120/C7125/C7130
Default Statusunknown
Version < 69.24.53
Version 0
Status affected
VendorXerox
Product Versalink C8000/C9000
Default Statusunknown
Version < 70.75.53
Version 0
Status affected
VendorXerox
Product Versalink C8000W
Default Statusunknown
Version < 72.75.53
Version 0
Status affected
VendorXerox
Product Phaser 6510
Default Statusunknown
Version < 64.75.53
Version 0
Status affected
VendorXerox
Product WorkCentre 6515
Default Statusunknown
Version < 65.75.53
Version 0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.421
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
10b61619-3869-496c-8a1e-f291b0e71e3f 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.