First published: Fri Apr 12 2019(Updated: )
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Credit: cert@airbus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Colorqube 8700 Firmware | <072.161.009.07200 | |
Xerox Colorqube 8700 | ||
Xerox Colorqube 8900 Firmware | <072.161.009.07200 | |
Xerox Colorqube 8900 | ||
Xerox Colorqube 9301 Firmware | <072.180.009.07200 | |
Xerox Colorqube 9301 | ||
Xerox Colorqube 9302 Firmware | <072.180.009.07200 | |
Xerox Colorqube 9302 | ||
Xerox Colorqube 9303 Firmware | <072.180.009.07200 | |
Xerox Colorqube 9303 |
A fix for some models is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10880 is a vulnerability within multiple XEROX products that allows remote command execution on the Linux system.
CVE-2019-10880 works by exploiting an OS Command Injection vulnerability in the HTTP interface of XEROX products.
The severity of CVE-2019-10880 is critical with a CVSS score of 9.8.
XEROX Colorqube 8700, XEROX Colorqube 8900, XEROX Colorqube 9301, XEROX Colorqube 9302, and XEROX Colorqube 9303 firmware versions up to exclusive 072.161.009.07200 and 072.180.009.07200 are affected.
To fix CVE-2019-10880, update XEROX Colorqube 8700, Colorqube 8900, Colorqube 9301, Colorqube 9302, and Colorqube 9303 firmware to version 072.161.009.07200 or 072.180.009.07200.