Vulnerability Description
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Workcentre 3655I Firmware | < 073.060.048.15000 |
| Xerox | Workcentre 3655I | - |
| Xerox | Workcentre 3655 Firmware | < 073.060.048.15000 |
| Xerox | Workcentre 3655 | - |
| Xerox | Workcentre 5890I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5890I | - |
| Xerox | Workcentre 5865I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5865I | - |
| Xerox | Workcentre 5875I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5875I | - |
| Xerox | Workcentre 5845 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5845 | - |
| Xerox | Workcentre 5865 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5865 | - |
| Xerox | Workcentre 5875 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5875 | - |
| Xerox | Workcentre 5890 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5890 | - |
| Xerox | Workcentre 5900 Firmware | < 073.091.048.15000 |
| Xerox | Workcentre 5900 | - |
Related Weaknesses (CWE)
References
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_SecurityVendor Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_SecurityVendor Advisory
FAQ
What is CVE-2018-20767?
CVE-2018-20767 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. Ther...
How severe is CVE-2018-20767?
CVE-2018-20767 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20767?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 3655I Firmware, Xerox Workcentre 3655I, Xerox Workcentre 3655 Firmware, Xerox Workcentre 3655, Xerox Workcentre 5890I Firmware.