CVE-2019-10880

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
12/04/2019
Last modified:
09/10/2019

Description

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xerox:colorqube_8700_firmware:*:*:*:*:*:*:*:* 072.161.009.07200 (excluding)
cpe:2.3:h:xerox:colorqube_8700:-:*:*:*:*:*:*:*
cpe:2.3:o:xerox:colorqube_8900_firmware:*:*:*:*:*:*:*:* 072.161.009.07200 (excluding)
cpe:2.3:h:xerox:colorqube_8900:-:*:*:*:*:*:*:*
cpe:2.3:o:xerox:colorqube_9301_firmware:*:*:*:*:*:*:*:* 072.180.009.07200 (excluding)
cpe:2.3:h:xerox:colorqube_9301:-:*:*:*:*:*:*:*
cpe:2.3:o:xerox:colorqube_9302_firmware:*:*:*:*:*:*:*:* 072.180.009.07200 (excluding)
cpe:2.3:h:xerox:colorqube_9302:-:*:*:*:*:*:*:*
cpe:2.3:o:xerox:colorqube_9303_firmware:*:*:*:*:*:*:*:* 072.180.009.07200 (excluding)
cpe:2.3:h:xerox:colorqube_9303:-:*:*:*:*:*:*:*