CVE-2021-28670: Critical severity xerox altalink firmware vulnerability
Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-28670?
CVE-2021-28670 is a vulnerability in Xerox AltaLink printers that allows unauthorized users to delete arbitrary files from the disk.
Which Xerox AltaLink models are affected by CVE-2021-28670?
Xerox AltaLink B8045/B8090, C8030/C8035, C8045/C8055, and C8070 models are affected by CVE-2021-28670.
What is the severity of CVE-2021-28670?
CVE-2021-28670 has a severity score of 9.1, which is classified as critical.
How can unauthorized users exploit CVE-2021-28670?
Unauthorized users can exploit CVE-2021-28670 by leveraging the Scan To Mailbox feature on the affected Xerox AltaLink printers.
Is there a fix available for CVE-2021-28670?
Yes, Xerox has released firmware updates to address CVE-2021-28670. Refer to the Xerox security bulletin for more information.