ZeroHour

CVE-2019-10880

CVSS 3.0
9.8 critical
EPSS
8%p95
Published
()
Modified
Description

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Vendors
xerox
Products
colorqube 8700 firmware, colorqube 8900 firmware, colorqube 9301 firmware, colorqube 9302 firmware, colorqube 9303 firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.