MEDIUM · 6.1

CVE-2020-26162

Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.

Vulnerability Description

Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
XeroxWorkcentre Ec7836 Firmware< 073.050.059.25300
XeroxWorkcentre Ec7836-
XeroxWorkcentre Ec7856 Firmware< 073.020.059.25300
XeroxWorkcentre Ec7856-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-26162?

CVE-2020-26162 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.

How severe is CVE-2020-26162?

CVE-2020-26162 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-26162?

Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre Ec7836 Firmware, Xerox Workcentre Ec7836, Xerox Workcentre Ec7856 Firmware, Xerox Workcentre Ec7856.