Vulnerability Description
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Altalink C8030 Firmware | < 100.001.028.05200 |
| Xerox | Altalink C8030 | - |
| Xerox | Altalink C8035 Firmware | < 100.001.028.05200 |
| Xerox | Altalink C8035 | - |
| Xerox | Altalink C8045 Firmware | < 100.002.028.05200 |
| Xerox | Altalink C8045 | - |
| Xerox | Altalink C8055 Firmware | < 100.002.028.05200 |
| Xerox | Altalink C8055 | - |
| Xerox | Altalink C8070 Firmware | < 100.003.028.05200 |
| Xerox | Altalink C8070 | - |
| Xerox | Altalink B8045 Firmware | < 100.008.028.05200 |
| Xerox | Altalink B8045 | - |
| Xerox | Altalink B8055 Firmware | < 100.008.028.05200 |
| Xerox | Altalink B8055 | - |
| Xerox | Altalink B8065 Firmware | < 100.008.028.05200 |
| Xerox | Altalink B8065 | - |
| Xerox | Altalink B8075 Firmware | < 100.008.028.05200 |
| Xerox | Altalink B8075 | - |
| Xerox | Altalink B8090 Firmware | < 100.008.028.05200 |
| Xerox | Altalink B8090 | - |
Related Weaknesses (CWE)
References
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/12/cert_SecurityVendor Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/12/cert_SecurityVendor Advisory
FAQ
What is CVE-2018-17172?
CVE-2018-17172 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthentica...
How severe is CVE-2018-17172?
CVE-2018-17172 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-17172?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Altalink C8030 Firmware, Xerox Altalink C8030, Xerox Altalink C8035 Firmware, Xerox Altalink C8035, Xerox Altalink C8045 Firmware.