Remote Command Execution Vulnerability in Xerox WorkCentre Devices
CVE-2018-20771
9.8CRITICAL
Summary
An issue has been identified in various Xerox WorkCentre devices where unauthenticated remote command execution can occur, posing significant security risks. This vulnerability allows attackers to execute arbitrary commands on the device without authentication, thus compromising the integrity and confidentiality of the system. Affected devices must update to the patched version R18-05 073.xxx.0487.15000 or later to mitigate this risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published