HIGH · 7.5

CVE-2006-5290

The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arb...

Vulnerability Description

The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname."

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
XeroxWorkcentre 232All versions
XeroxWorkcentre 238All versions
XeroxWorkcentre 245All versions
XeroxWorkcentre 255All versions
XeroxWorkcentre 265All versions
XeroxWorkcentre 275All versions

References

FAQ

What is CVE-2006-5290?

CVE-2006-5290 is a vulnerability with a CVSS score of 7.5 (HIGH). The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arb...

How severe is CVE-2006-5290?

CVE-2006-5290 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5290?

Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 232, Xerox Workcentre 238, Xerox Workcentre 245, Xerox Workcentre 255, Xerox Workcentre 265.