CVE-2018-17172: Command Injection
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17172?
The severity of CVE-2018-17172 is critical.
Which Xerox devices are affected by CVE-2018-17172?
Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices are affected by CVE-2018-17172.
What is the vulnerability in CVE-2018-17172?
CVE-2018-17172 is a vulnerability that allows unauthenticated command injection in Xerox AltaLink devices.
How can I fix CVE-2018-17172?
To fix CVE-2018-17172, update the firmware of Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices to version 100.008.028.05200, 100.001.028.05200, 100.002.028.05200, or 100.003.028.05200 respectively.
Where can I find more information about CVE-2018-17172?
You can find more information about CVE-2018-17172 in the security documentation provided by Xerox.