Remote Command Execution Vulnerability in Xerox Printers and Multifunction Devices
CVE-2021-28671
9.8CRITICAL
Summary
A remote command execution vulnerability exists in the Web User Interface of several models of Xerox printers and multifunction devices. This flaw permits remote attackers, using a specifically crafted or weaponized clone file, to execute arbitrary commands on the devices. The vulnerability affects various versions of models such as the Xerox Phaser, WorkCentre, and VersaLink, necessitating immediate attention and remediation to safeguard against unauthorized access and potential exploitation.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved