CVE-2020-9330

Summary

CVECVE-2020-9330
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-02-21 23:15:00 UTC
Updated2021-07-21 11:39:00 UTC
DescriptionCertain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.

Risk And Classification

Problem Types: CWE-306

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Xerox Workcentre 3655 - All All All
Hardware Xerox Workcentre 3655 - All All All
Hardware Xerox Workcentre 3655i - All All All
Hardware Xerox Workcentre 3655i - All All All
Operating System Xerox Workcentre 3655i Firmware All All All All
Operating System Xerox Workcentre 3655i Firmware All All All All
Operating System Xerox Workcentre 3655 Firmware All All All All
Operating System Xerox Workcentre 3655 Firmware All All All All
Hardware Xerox Workcentre 5845 - All All All
Hardware Xerox Workcentre 5845 - All All All
Operating System Xerox Workcentre 5845 Firmware All All All All
Operating System Xerox Workcentre 5845 Firmware All All All All
Hardware Xerox Workcentre 5855 - All All All
Hardware Xerox Workcentre 5855 - All All All
Operating System Xerox Workcentre 5855 Firmware All All All All
Operating System Xerox Workcentre 5855 Firmware All All All All
Hardware Xerox Workcentre 5945 - All All All
Hardware Xerox Workcentre 5945 - All All All
Operating System Xerox Workcentre 5945 Firmware All All All All
Operating System Xerox Workcentre 5945 Firmware All All All All
Hardware Xerox Workcentre 5955 - All All All
Hardware Xerox Workcentre 5955 - All All All
Operating System Xerox Workcentre 5955 Firmware All All All All
Operating System Xerox Workcentre 5955 Firmware All All All All
Hardware Xerox Workcentre 6655 - All All All
Hardware Xerox Workcentre 6655 - All All All
Hardware Xerox Workcentre 6655i - All All All
Hardware Xerox Workcentre 6655i - All All All
Operating System Xerox Workcentre 6655i Firmware All All All All
Operating System Xerox Workcentre 6655i Firmware All All All All
Operating System Xerox Workcentre 6655 Firmware All All All All
Operating System Xerox Workcentre 6655 Firmware All All All All
Hardware Xerox Workcentre 7220 - All All All
Hardware Xerox Workcentre 7220 - All All All
Operating System Xerox Workcentre 7220 Firmware All All All All
Operating System Xerox Workcentre 7220 Firmware All All All All
Hardware Xerox Workcentre 7225 - All All All
Hardware Xerox Workcentre 7225 - All All All
Operating System Xerox Workcentre 7225 Firmware All All All All
Operating System Xerox Workcentre 7225 Firmware All All All All
Hardware Xerox Workcentre 7830 - All All All
Hardware Xerox Workcentre 7830 - All All All
Operating System Xerox Workcentre 7830 Firmware All All All All
Operating System Xerox Workcentre 7830 Firmware All All All All
Hardware Xerox Workcentre 7835 - All All All
Hardware Xerox Workcentre 7835 - All All All
Operating System Xerox Workcentre 7835 Firmware All All All All
Operating System Xerox Workcentre 7835 Firmware All All All All
Hardware Xerox Workcentre 7845 - All All All
Hardware Xerox Workcentre 7845 - All All All
Operating System Xerox Workcentre 7845 Firmware All All All All
Operating System Xerox Workcentre 7845 Firmware All All All All
Hardware Xerox Workcentre 7855 - All All All
Hardware Xerox Workcentre 7855 - All All All
Operating System Xerox Workcentre 7855 Firmware All All All All
Operating System Xerox Workcentre 7855 Firmware All All All All
Hardware Xerox Workcentre 7970 - All All All
Hardware Xerox Workcentre 7970 - All All All
Hardware Xerox Workcentre 7970i - All All All
Hardware Xerox Workcentre 7970i - All All All
Operating System Xerox Workcentre 7970i Firmware All All All All
Operating System Xerox Workcentre 7970i Firmware All All All All
Operating System Xerox Workcentre 7970 Firmware All All All All
Operating System Xerox Workcentre 7970 Firmware All All All All
Hardware Xerox Workcentre Ec7836 - All All All
Hardware Xerox Workcentre Ec7836 - All All All
Operating System Xerox Workcentre Ec7836 Firmware All All All All
Operating System Xerox Workcentre Ec7836 Firmware All All All All
Hardware Xerox Workcentre Ec7856 - All All All
Hardware Xerox Workcentre Ec7856 - All All All
Operating System Xerox Workcentre Ec7856 Firmware All All All All
Operating System Xerox Workcentre Ec7856 Firmware All All All All

References

ReferenceSourceLinkTags
securitydocs.business.xerox.com/wp-content/uploads/2020/02/cert_Security_Mini_Bulletin_XRX20D... MISC securitydocs.business.xerox.com Patch, Vendor Advisory
Hackers Can Gain Active Directory Privileges Through Vulnerability in Xerox Printers - Securicon MISC www.securicon.com Exploit, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report