CRITICAL · 9.8

CVE-2018-20768

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An a...

Vulnerability Description

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XeroxWorkcentre 3655I Firmware< 073.060.048.15000
XeroxWorkcentre 3655I-
XeroxWorkcentre 3655 Firmware< 073.060.048.15000
XeroxWorkcentre 3655-
XeroxWorkcentre 5890I Firmware< 073.190.048.15000
XeroxWorkcentre 5890I-
XeroxWorkcentre 5865I Firmware< 073.190.048.15000
XeroxWorkcentre 5865I-
XeroxWorkcentre 5875I Firmware< 073.190.048.15000
XeroxWorkcentre 5875I-
XeroxWorkcentre 5845 Firmware< 073.190.048.15000
XeroxWorkcentre 5845-
XeroxWorkcentre 5865 Firmware< 073.190.048.15000
XeroxWorkcentre 5865-
XeroxWorkcentre 5875 Firmware< 073.190.048.15000
XeroxWorkcentre 5875-
XeroxWorkcentre 5890 Firmware< 073.190.048.15000
XeroxWorkcentre 5890-
XeroxWorkcentre 5900 Firmware< 073.091.048.15000
XeroxWorkcentre 5900-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-20768?

CVE-2018-20768 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An a...

How severe is CVE-2018-20768?

CVE-2018-20768 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-20768?

Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 3655I Firmware, Xerox Workcentre 3655I, Xerox Workcentre 3655 Firmware, Xerox Workcentre 3655, Xerox Workcentre 5890I Firmware.