First published: Sun Dec 10 2006(Updated: )
Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Workcentre 255 | ||
Xerox Workcentre 245 | ||
Xerox Workcentre 238 | ||
Xerox Workcentre 232 | ||
Xerox Workcentre 232 | ||
Xerox Workcentre 265 | ||
Xerox Workcentre 245 | ||
Xerox Workcentre 238 | ||
Xerox Workcentre 275 | ||
Xerox Workcentre 255 | ||
Xerox Workcentre 275 | ||
Xerox Workcentre 265 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6434 is considered a high severity vulnerability due to its potential to allow remote attackers to bypass authentication controls.
The recommended fix for CVE-2006-6434 is to update to the latest firmware version for affected Xerox WorkCentre models.
CVE-2006-6434 affects Xerox WorkCentre models prior to versions 12.050.03.000, 13.050.03.000, and 14.050.03.000.
Yes, CVE-2006-6434 can be exploited by remote attackers, allowing them to bypass authentication without physical access.
While there are no specific workarounds available, it is advisable to restrict network access to the affected devices to mitigate risk until an update can be applied.