CVE-2019-18629: High severity xerox altalink firmware vulnerability
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a compromised private key.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Xerox printer vulnerability?
The vulnerability ID for this Xerox printer vulnerability is CVE-2019-18629.
What is the severity of CVE-2019-18629?
The severity of CVE-2019-18629 is high with a CVSS score of 8.1.
Which Xerox printer models are affected by CVE-2019-18629?
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers are affected by CVE-2019-18629.
How can an attacker exploit CVE-2019-18629?
An attacker can exploit CVE-2019-18629 by executing an unwanted binary during an exploited clone install on the affected Xerox printers.
Where can I find more information about CVE-2019-18629?
You can find more information about CVE-2019-18629 in the Xerox security bulletin at https://securitydocs.business.xerox.com/wp-content/uploads/2021/03/cert_Security_Mini_Bulletin_XRX19AI_for_ALB80xx-C80xx_v1.1.pdf.