Vulnerability Description
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Workcentre 3655I Firmware | < 073.060.048.15000 |
| Xerox | Workcentre 3655I | - |
| Xerox | Workcentre 3655 Firmware | < 073.060.048.15000 |
| Xerox | Workcentre 3655 | - |
| Xerox | Workcentre 5890I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5890I | - |
| Xerox | Workcentre 5865I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5865I | - |
| Xerox | Workcentre 5875I Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5875I | - |
| Xerox | Workcentre 5845 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5845 | - |
| Xerox | Workcentre 5865 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5865 | - |
| Xerox | Workcentre 5875 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5875 | - |
| Xerox | Workcentre 5890 Firmware | < 073.190.048.15000 |
| Xerox | Workcentre 5890 | - |
| Xerox | Workcentre 5900 Firmware | < 073.091.048.15000 |
| Xerox | Workcentre 5900 | - |
Related Weaknesses (CWE)
References
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_SecurityPatchVendor Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_SecurityPatchVendor Advisory
FAQ
What is CVE-2018-20768?
CVE-2018-20768 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An a...
How severe is CVE-2018-20768?
CVE-2018-20768 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-20768?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 3655I Firmware, Xerox Workcentre 3655I, Xerox Workcentre 3655 Firmware, Xerox Workcentre 3655, Xerox Workcentre 5890I Firmware.