First published: Mon Mar 29 2021(Updated: )
Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Altalink B8045 Firmware | <103.008.020.23120 | |
Xerox AltaLink B8045 | ||
Xerox Altalink B8055 Firmware | <103.008.020.23120 | |
Xerox Altalink B8055 | ||
Xerox Altalink B8065 Firmware | <103.008.020.23120 | |
Xerox Altalink B8065 | ||
Xerox Altalink B8075 Firmware | <103.008.020.23120 | |
Xerox Altalink B8075 | ||
Xerox Altalink B8090 Firmware | <103.008.020.23120 | |
Xerox Altalink B8090 | ||
Xerox Altalink C8030 Firmware | <103.001.020.23120 | |
Xerox Altalink C8030 | ||
Xerox Altalink C8035 Firmware | <103.001.020.23120 | |
Xerox AltaLink C8035 | ||
Xerox Altalink C8045 Firmware | <103.002.020.23120 | |
Xerox Altalink C8045 | ||
Xerox Altalink C8055 Firmware | <103.002.020.23120 | |
Xerox Altalink C8055 | ||
Xerox Altalink C8070 Firmware | <103.003.020.23120 | |
Xerox Altalink C8070 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28670 is a vulnerability in Xerox AltaLink printers that allows unauthorized users to delete arbitrary files from the disk.
Xerox AltaLink B8045/B8090, C8030/C8035, C8045/C8055, and C8070 models are affected by CVE-2021-28670.
CVE-2021-28670 has a severity score of 9.1, which is classified as critical.
Unauthorized users can exploit CVE-2021-28670 by leveraging the Scan To Mailbox feature on the affected Xerox AltaLink printers.
Yes, Xerox has released firmware updates to address CVE-2021-28670. Refer to the Xerox security bulletin for more information.