CVE-2019-10880
12.04.2019, 18:29
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Vendor | Product | Version |
---|---|---|
xerox | colorqube_8700_firmware | 𝑥 < 072.161.009.07200 |
xerox | colorqube_8900_firmware | 𝑥 < 072.161.009.07200 |
xerox | colorqube_9301_firmware | 𝑥 < 072.180.009.07200 |
xerox | colorqube_9302_firmware | 𝑥 < 072.180.009.07200 |
xerox | colorqube_9303_firmware | 𝑥 < 072.180.009.07200 |
𝑥
= Vulnerable software versions
References