HIGH · 7.8

CVE-2006-6430

Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensiti...

Vulnerability Description

Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XeroxWorkcentre 232All versions
XeroxWorkcentre 238All versions
XeroxWorkcentre 245All versions
XeroxWorkcentre 255All versions
XeroxWorkcentre 265All versions
XeroxWorkcentre 275All versions

References

FAQ

What is CVE-2006-6430?

CVE-2006-6430 is a vulnerability with a CVSS score of 7.8 (HIGH). Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensiti...

How severe is CVE-2006-6430?

CVE-2006-6430 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6430?

Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 232, Xerox Workcentre 238, Xerox Workcentre 245, Xerox Workcentre 255, Xerox Workcentre 265.