Vulnerability Description
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Versalink Firmware | <= 42.01 |
| Xerox | Versalink B400 | - |
| Xerox | Versalink B405 | - |
| Xerox | Versalink B600 | - |
| Xerox | Versalink B610 | - |
| Xerox | Versalink B7025 | - |
| Xerox | Versalink B7030 | - |
| Xerox | Versalink B7035 | - |
| Xerox | Versalink C400 | - |
| Xerox | Versalink C405 | - |
| Xerox | Versalink C500 | - |
| Xerox | Versalink C505 | - |
| Xerox | Versalink C600 | - |
| Xerox | Versalink C605 | - |
| Xerox | Versalink C7000 | - |
| Xerox | Versalink C7020 | - |
| Xerox | Versalink C7025 | - |
| Xerox | Versalink C7030 | - |
| Xerox | Versalink C8000 | - |
| Xerox | Versalink C8000W | - |
Related Weaknesses (CWE)
References
- https://neosmart.net/blog/2022/xerox-vulnerability-allows-unauthenticated-networExploitThird Party Advisory
- https://twitter.com/mqudsi/status/1485756915187695618Third Party Advisory
- https://neosmart.net/blog/2022/xerox-vulnerability-allows-unauthenticated-networExploitThird Party Advisory
- https://twitter.com/mqudsi/status/1485756915187695618Third Party Advisory
FAQ
What is CVE-2022-23968?
CVE-2022-23968 is a vulnerability with a CVSS score of 7.5 (HIGH). Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a perman...
How severe is CVE-2022-23968?
CVE-2022-23968 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23968?
Check the references section above for vendor advisories and patch information. Affected products include: Xerox Versalink Firmware, Xerox Versalink B400, Xerox Versalink B405, Xerox Versalink B600, Xerox Versalink B610.