CVE-2016-11061: OS Command Injection
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-11061?
CVE-2016-11061 is a vulnerability in Xerox WorkCentre devices that allows an unauthenticated attacker to execute OS commands.
What is the severity level of CVE-2016-11061?
CVE-2016-11061 has a severity level of critical.
How does CVE-2016-11061 affect Xerox WorkCentre devices?
CVE-2016-11061 affects Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410.
How can an attacker exploit CVE-2016-11061?
An unauthenticated attacker can exploit CVE-2016-11061 by executing OS commands through the support/remoteUI/configrui.php script.
Is there a fix for CVE-2016-11061?
Yes, updating Xerox WorkCentre devices to version 073.xxx.086.15410 or later will fix CVE-2016-11061.