First published: Mon Dec 11 2006(Updated: )
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox WorkCentre | <=13.050.02.000 | |
Xerox WorkCentre | <=14.050.02.000 | |
Xerox WorkCentre | <=13.050.02.000 | |
Xerox WorkCentre | <=14.050.02.000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-6468 is currently unknown as it has no publicly available exploit information.
To fix CVE-2006-6468, users should upgrade to the latest firmware version 12.050.03.000 or newer for the affected Xerox WorkCentre devices.
CVE-2006-6468 affects Xerox WorkCentre and WorkCentre Pro versions prior to 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000.
The impact of CVE-2006-6468 could potentially lead to exploitation through spoofed certificates during SSL certificate validation.
Currently, there are no documented workarounds for CVE-2006-6468, and upgrading to the fixed versions is recommended.