Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.

Project Subscriptions

Vendors Products
Workcentre 3655 Subscribe
Workcentre 3655 Firmware Subscribe
Workcentre 3655i Subscribe
Workcentre 3655i Firmware Subscribe
Workcentre 5865 Subscribe
Workcentre 5865 Firmware Subscribe
Workcentre 5865i Subscribe
Workcentre 5865i Firmware Subscribe
Workcentre 5875 Subscribe
Workcentre 5875 Firmware Subscribe
Workcentre 5875i Subscribe
Workcentre 5875i Firmware Subscribe
Workcentre 5890 Subscribe
Workcentre 5890 Firmware Subscribe
Workcentre 5890i Subscribe
Workcentre 5890i Firmware Subscribe
Workcentre 5945 Subscribe
Workcentre 5945 Firmware Subscribe
Workcentre 5945i Subscribe
Workcentre 5945i Firmware Subscribe
Workcentre 5955 Subscribe
Workcentre 5955 Firmware Subscribe
Workcentre 5955i Subscribe
Workcentre 5955i Firmware Subscribe
Workcentre 6655 Subscribe
Workcentre 6655 Firmware Subscribe
Workcentre 6655i Subscribe
Workcentre 6655i Firmware Subscribe
Workcentre 7200 Subscribe
Workcentre 7200 Firmware Subscribe
Workcentre 7200i Subscribe
Workcentre 7200i Firmware Subscribe
Workcentre 7220 Subscribe
Workcentre 7220 Firmware Subscribe
Workcentre 7225 Subscribe
Workcentre 7225 Firmware Subscribe
Workcentre 7225i Subscribe
Workcentre 7225i Firmware Subscribe
Workcentre 7830 Subscribe
Workcentre 7830 Firmware Subscribe
Workcentre 7835 Subscribe
Workcentre 7835 Firmware Subscribe
Workcentre 7845 Subscribe
Workcentre 7845 Firmware Subscribe
Workcentre 7855 Subscribe
Workcentre 7855 Firmware Subscribe
Workcentre 7970 Subscribe
Workcentre 7970 Firmware Subscribe
Workcentre 7970i Subscribe
Workcentre 7970i Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2016-2050 Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T03:47:34.938Z

Reserved: 2020-04-29T00:00:00.000Z

Link: CVE-2016-11061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-29T22:15:11.810

Modified: 2024-11-21T02:45:24.550

Link: CVE-2016-11061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses