Vulnerability Description
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Workcentre 3655 Firmware | < 075.060.000.12010 |
| Xerox | Workcentre 3655 | - |
| Xerox | Workcentre 3655I Firmware | < 075.060.000.12010 |
| Xerox | Workcentre 3655I | - |
| Xerox | Workcentre 5865 Firmware | < 075.190.010.12010 |
| Xerox | Workcentre 5865 | - |
| Xerox | Workcentre 5875 Firmware | < 075.190.010.12010 |
| Xerox | Workcentre 5875 | - |
| Xerox | Workcentre 5890 Firmware | < 075.190.010.12010 |
| Xerox | Workcentre 5890 | - |
| Xerox | Workcentre 5865I Firmware | < 075.190.010.12010 |
| Xerox | Workcentre 5865I | - |
| Xerox | Workcentre 5875I Firmware | < 075.190.010.12010 |
| Xerox | Workcentre 5875I | - |
| Xerox | Workcentre 5945 Firmware | < 075.091.010.12010 |
| Xerox | Workcentre 5945 | - |
| Xerox | Workcentre 5955 Firmware | < 075.091.010.12010 |
| Xerox | Workcentre 5955 | - |
| Xerox | Workcentre 5945I Firmware | < 075.091.010.12010 |
| Xerox | Workcentre 5945I | - |
Related Weaknesses (CWE)
References
- https://securitydocs.business.xerox.com/wp-content/uploads/2020/06/cert_SecurityPatchVendor Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2020/06/cert_SecurityPatchVendor Advisory
FAQ
What is CVE-2020-36201?
CVE-2020-36201 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 797...
How severe is CVE-2020-36201?
CVE-2020-36201 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36201?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Workcentre 3655 Firmware, Xerox Workcentre 3655, Xerox Workcentre 3655I Firmware, Xerox Workcentre 3655I, Xerox Workcentre 5865 Firmware.