CVE-2018-20770: SQL Injection
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20770?
CVE-2018-20770 has a moderate severity level due to the potential for blind SQL injection that could lead to unauthorized data exposure.
How do I fix CVE-2018-20770?
To fix CVE-2018-20770, upgrade to the firmware version R18-05 073.xxx.0487.15000 or later for the affected Xerox devices.
What devices are affected by CVE-2018-20770?
CVE-2018-20770 affects various Xerox WorkCentre models including 3655, 3655i, 58XX, 59XX, and several others prior to the specified firmware updates.
What type of vulnerability is CVE-2018-20770?
CVE-2018-20770 is classified as a blind SQL injection vulnerability, allowing attackers to exploit improper validation of input.
What precautions should I take regarding CVE-2018-20770?
Ensure that your Xerox WorkCentre devices are updated with the latest firmware to mitigate the risks associated with CVE-2018-20770.