CVE-2018-20768: Code Injection
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20768?
CVE-2018-20768 has a high severity rating due to the ability of an attacker to execute arbitrary PHP code.
How do I fix CVE-2018-20768?
To fix CVE-2018-20768, update the firmware of your affected Xerox WorkCentre device to version R18-05 073.xxx.0487.15000 or later.
Which devices are affected by CVE-2018-20768?
CVE-2018-20768 affects multiple Xerox WorkCentre models including 3655, 3685, 58XX series, 59XX series, and others prior to specific firmware updates.
What kind of attack is facilitated by CVE-2018-20768?
CVE-2018-20768 allows an attacker to write to a specific file leading to arbitrary code execution, posing a significant security risk.
Is there a public reference for CVE-2018-20768?
Yes, Xerox has released a mini bulletin detailing CVE-2018-20768 and necessary actions to mitigate the vulnerability.