First published: Sun Dec 10 2006(Updated: )
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Workcentre 255 | ||
Xerox Workcentre 245 | ||
Xerox Workcentre 238 | ||
Xerox Workcentre 232 | ||
Xerox Workcentre 232 | ||
Xerox Workcentre 265 | ||
Xerox Workcentre 245 | ||
Xerox Workcentre 238 | ||
Xerox Workcentre 275 | ||
Xerox Workcentre 255 | ||
Xerox Workcentre 275 | ||
Xerox Workcentre 265 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6441 is considered a high severity vulnerability as it allows unauthorized local users to bypass security controls.
To fix CVE-2006-6441, update your Xerox WorkCentre or WorkCentre Pro device to the latest firmware version available.
CVE-2006-6441 affects various models of Xerox WorkCentre and WorkCentre Pro devices, specifically those before certain firmware thresholds.
Attackers can exploit CVE-2006-6441 to boot the Alchemy operating system via unauthorized alternate boot media.
CVE-2006-6441 is a local vulnerability, meaning it requires physical access to the affected device to be exploited.