CVE-2019-10880: OS Command Injection
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-10880?
CVE-2019-10880 is a vulnerability within multiple XEROX products that allows remote command execution on the Linux system.
How does CVE-2019-10880 work?
CVE-2019-10880 works by exploiting an OS Command Injection vulnerability in the HTTP interface of XEROX products.
What is the severity of CVE-2019-10880?
The severity of CVE-2019-10880 is critical with a CVSS score of 9.8.
Which XEROX products are affected by CVE-2019-10880?
XEROX Colorqube 8700, XEROX Colorqube 8900, XEROX Colorqube 9301, XEROX Colorqube 9302, and XEROX Colorqube 9303 firmware versions up to exclusive 072.161.009.07200 and 072.180.009.07200 are affected.
How can I fix CVE-2019-10880?
To fix CVE-2019-10880, update XEROX Colorqube 8700, Colorqube 8900, Colorqube 9301, Colorqube 9302, and Colorqube 9303 firmware to version 072.161.009.07200 or 072.180.009.07200.