CVE-2021-28671
Summary
| CVE | CVE-2021-28671 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-29 21:15:00 UTC |
| Updated | 2021-04-05 20:21:00 UTC |
| Description | Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35 before 58.65.51 and 58.59.11 (Bridge), C400 before 67.65.51 and 67.59.01 (Bridge), C405 before 68.65.51 and 68.59.01 (Bridge), C500/C600 before 61.65.51 and 61.59.01 (Bridge), C505/C605 before 62.65.51 and 62.59.01 (Bridge), C7000 before 56.65.51 and 56.59.01 (Bridge), C7020/25/30 before 57.65.51 and 57.59.01 (Bridge), C8000/C9000 before 70.65.51 and 70.59.01 (Bridge), C8000W before 72.65.51 have a remote Command Execution vulnerability in the Web User Interface that allows remote attackers with "a weaponized clone file" to execute arbitrary commands. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Xerox | Phaser 6510 | - | All | All | All |
| Operating System | Xerox | Phaser 6510 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B400 | - | All | All | All |
| Operating System | Xerox | Versalink B400 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B405 | - | All | All | All |
| Operating System | Xerox | Versalink B405 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B600 | - | All | All | All |
| Operating System | Xerox | Versalink B600 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B605 | - | All | All | All |
| Operating System | Xerox | Versalink B605 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B610 | - | All | All | All |
| Operating System | Xerox | Versalink B610 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B615 | - | All | All | All |
| Operating System | Xerox | Versalink B615 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B7025 | - | All | All | All |
| Operating System | Xerox | Versalink B7025 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B7030 | - | All | All | All |
| Operating System | Xerox | Versalink B7030 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink B7035 | - | All | All | All |
| Operating System | Xerox | Versalink B7035 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C400 | - | All | All | All |
| Operating System | Xerox | Versalink C400 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C405 | - | All | All | All |
| Operating System | Xerox | Versalink C405 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C500 | - | All | All | All |
| Operating System | Xerox | Versalink C500 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C505 | - | All | All | All |
| Operating System | Xerox | Versalink C505 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C600 | - | All | All | All |
| Operating System | Xerox | Versalink C600 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C605 | - | All | All | All |
| Operating System | Xerox | Versalink C605 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C7000 | - | All | All | All |
| Operating System | Xerox | Versalink C7000 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C7020 | - | All | All | All |
| Operating System | Xerox | Versalink C7020 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C7025 | - | All | All | All |
| Operating System | Xerox | Versalink C7025 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C7030 | - | All | All | All |
| Operating System | Xerox | Versalink C7030 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C8000 | - | All | All | All |
| Hardware | Xerox | Versalink C8000w | - | All | All | All |
| Operating System | Xerox | Versalink C8000w Firmware | All | All | All | All |
| Operating System | Xerox | Versalink C8000 Firmware | All | All | All | All |
| Hardware | Xerox | Versalink C9000 | - | All | All | All |
| Operating System | Xerox | Versalink C9000 Firmware | All | All | All | All |
| Hardware | Xerox | Workcentre 6515 | - | All | All | All |
| Operating System | Xerox | Workcentre 6515 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| securitydocs.business.xerox.com/wp-content/uploads/2021/03/cert_Security_Mini_Bulletin_XRX21D... | CONFIRM | securitydocs.business.xerox.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.