7.6
CVE-2024-12511
- EPSS 0.2%
- Veröffentlicht 03.02.2025 20:15:32
- Zuletzt bearbeitet 17.09.2025 12:15:36
- Quelle 10b61619-3869-496c-8a1e-f291b0
- Teams Watchlist Login
- Unerledigt Login
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerXerox
≫
Produkt
Versalink B400
Default Statusunknown
Version <
37.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink B405
Default Statusunknown
Version <
38.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C400
Default Statusunknown
Version <
67.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C405
Default Statusunknown
Version <
68.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink B600/B610
Default Statusunknown
Version <
32.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink B605/B615
Default Statusunknown
Version <
33.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C500/C600
Default Statusunknown
Version <
61.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C505/C605
Default Statusunknown
Version <
62.82.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C7000
Default Statusunknown
Version <
56.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C7020/C7025/C7030
Default Statusunknown
Version <
57.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink B7025/B7030/B7035
Default Statusunknown
Version <
58.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink B7125/B7130/B7135
Default Statusunknown
Version <
59.24.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C7120/C7125/C7130
Default Statusunknown
Version <
69.24.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C8000/C9000
Default Statusunknown
Version <
70.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Versalink C8000W
Default Statusunknown
Version <
72.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
Phaser 6510
Default Statusunknown
Version <
64.75.53
Version
0
Status
affected
HerstellerXerox
≫
Produkt
WorkCentre 6515
Default Statusunknown
Version <
65.75.53
Version
0
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.421 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
10b61619-3869-496c-8a1e-f291b0e71e3f | 7.6 | 2.8 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.