HIGH · 7.5

CVE-2020-36201

An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 797...

Vulnerability Description

An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XeroxWorkcentre 3655 Firmware< 075.060.000.12010
XeroxWorkcentre 3655-
XeroxWorkcentre 3655I Firmware< 075.060.000.12010
XeroxWorkcentre 3655I-
XeroxWorkcentre 5865 Firmware< 075.190.010.12010
XeroxWorkcentre 5865-
XeroxWorkcentre 5875 Firmware< 075.190.010.12010
XeroxWorkcentre 5875-
XeroxWorkcentre 5890 Firmware< 075.190.010.12010
XeroxWorkcentre 5890-
XeroxWorkcentre 5865I Firmware< 075.190.010.12010
XeroxWorkcentre 5865I-
XeroxWorkcentre 5875I Firmware< 075.190.010.12010
XeroxWorkcentre 5875I-
XeroxWorkcentre 5945 Firmware< 075.091.010.12010
XeroxWorkcentre 5945-
XeroxWorkcentre 5955 Firmware< 075.091.010.12010
XeroxWorkcentre 5955-
XeroxWorkcentre 5945I Firmware< 075.091.010.12010
XeroxWorkcentre 5945I-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-36201?

CVE-2020-36201 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 797...

How severe is CVE-2020-36201?

CVE-2020-36201 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-36201?

Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 3655 Firmware, Xerox Workcentre 3655, Xerox Workcentre 3655I Firmware, Xerox Workcentre 3655I, Xerox Workcentre 5865 Firmware.