CVE-2018-20769
published 2019-02-10CVE-2018-20769: An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.44%
69.8th percentile
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xerox | workcentre_3655_firmware | < 073.060.048.15000 | 073.060.048.15000 |
| xerox | workcentre_3655i_firmware | < 073.060.048.15000 | 073.060.048.15000 |
| xerox | workcentre_5845_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5865_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5865i_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5875_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5875i_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5890_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5890i_firmware | < 073.190.048.15000 | 073.190.048.15000 |
| xerox | workcentre_5900_firmware | < 073.091.048.15000 | 073.091.048.15000 |
| xerox | workcentre_5900i_firmware | < 073.091.048.15000 | 073.091.048.15000 |
| xerox | workcentre_6655_firmware | < 073.110.048.15000 | 073.110.048.15000 |
| xerox | workcentre_6655i_firmware | < 073.110.048.15000 | 073.110.048.15000 |
| xerox | workcentre_7220_firmware | < 073.030.048.15000 | 073.030.048.15000 |
| xerox | workcentre_7220i_firmware | < 073.030.048.15000 | 073.030.048.15000 |
| xerox | workcentre_7225_firmware | < 073.030.048.15000 | 073.030.048.15000 |
| xerox | workcentre_7225i_firmware | < 073.030.048.15000 | 073.030.048.15000 |
| xerox | workcentre_7830_firmware | < 073.010.048.15000 | 073.010.048.15000 |
| xerox | workcentre_7830i_firmware | < 073.010.048.15000 | 073.010.048.15000 |
| xerox | workcentre_7835_firmware | < 073.010.048.15000 | 073.010.048.15000 |
| xerox | workcentre_7835i_firmware | < 073.010.048.15000 | 073.010.048.15000 |
| xerox | workcentre_7845_firmware | < 073.040.048.15000 | 073.040.048.15000 |
| xerox | workcentre_7845i_firmware | < 073.040.048.15000 | 073.040.048.15000 |
| xerox | workcentre_7855_firmware | < 073.040.048.15000 | 073.040.048.15000 |
| xerox | workcentre_7855i_firmware | < 073.040.048.15000 | 073.040.048.15000 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-10
Published