{"api_version":"1","generated_at":"2026-07-23T11:37:20+00:00","cve":"CVE-2006-0825","urls":{"html":"https://cve.report/CVE-2006-0825","api":"https://cve.report/api/cve/CVE-2006-0825.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0825","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0825"},"summary":{"title":"CVE-2006-0825","description":"Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain \"unauthorized network access\" via unknown attack vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-02-21 23:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/16726","name":"http://www.securityfocus.com/bid/16726","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xerox WorkCentre Products Local Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf","name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0668","name":"http://www.vupen.com/english/advisories/2006/0668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24804","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015648","name":"http://securitytracker.com/id?1015648","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Xerox WorkCentre Multiple Bugs in ESS/Network Controller and MicroServer Web Server Permit Remote Access, Denial of Service, and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/23359","name":"http://www.osvdb.org/23359","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/18952","name":"http://secunia.com/advisories/18952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Xerox ESS/ Network Controller and MicroServer Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0825","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0825","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_232","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_232","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_238","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_238","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_245","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_245","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_255","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_255","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_265","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_265","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_275","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"xerox","cpe5":"workcentre_275","cpe6":"*","cpe7":"*","cpe8":"pro","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"825","cve":"CVE-2006-0825","epss":"0.010780000","percentile":"0.778600000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:48:56.214Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16726","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16726"},{"name":"ADV-2006-0668","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0668"},{"name":"1015648","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015648"},{"name":"18952","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18952"},{"name":"xerox-workcentre-auth-bypass(24804)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24804"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"},{"name":"23359","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23359"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain \"unauthorized network access\" via unknown attack vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16726","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16726"},{"name":"ADV-2006-0668","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0668"},{"name":"1015648","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015648"},{"name":"18952","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18952"},{"name":"xerox-workcentre-auth-bypass(24804)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24804"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"},{"name":"23359","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23359"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0825","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain \"unauthorized network access\" via unknown attack vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16726","refsource":"BID","url":"http://www.securityfocus.com/bid/16726"},{"name":"ADV-2006-0668","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0668"},{"name":"1015648","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015648"},{"name":"18952","refsource":"SECUNIA","url":"http://secunia.com/advisories/18952"},{"name":"xerox-workcentre-auth-bypass(24804)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24804"},{"name":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf","refsource":"CONFIRM","url":"http://www.xerox.com/downloads/usa/en/c/cert_XRX06_001.pdf"},{"name":"23359","refsource":"OSVDB","url":"http://www.osvdb.org/23359"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0825","datePublished":"2006-02-21T23:00:00.000Z","dateReserved":"2006-02-21T00:00:00.000Z","dateUpdated":"2024-08-07T16:48:56.214Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-02-21 23:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_232:*:*:*:*:*:*:*:*","matchCriteriaId":"24E761E4-0B6C-4C2A-BFCA-4CFC5620E91C"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_232:*:*:pro:*:*:*:*:*","matchCriteriaId":"74245D08-446A-4988-BCFD-85509C4CE340"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_238:*:*:*:*:*:*:*:*","matchCriteriaId":"12790FD1-DECA-4074-9458-3F88823190EF"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_238:*:*:pro:*:*:*:*:*","matchCriteriaId":"88E2F705-B185-4211-B0CC-1E295E5B4471"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_245:*:*:*:*:*:*:*:*","matchCriteriaId":"7D7FE90B-21E6-4628-AD70-37BB9644CBD9"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_245:*:*:pro:*:*:*:*:*","matchCriteriaId":"573640FF-609D-4441-B7DD-3477F239A00E"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_255:*:*:*:*:*:*:*:*","matchCriteriaId":"8204B5C0-0B87-48BD-9678-5101B048C135"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_255:*:*:pro:*:*:*:*:*","matchCriteriaId":"3A2128EF-5847-4097-84BC-5CAC270F1C10"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_265:*:*:*:*:*:*:*:*","matchCriteriaId":"BAE44F85-3F9A-45FC-A411-1D1B4C2E33D7"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_265:*:*:pro:*:*:*:*:*","matchCriteriaId":"D8FD8F59-E229-4138-9B85-7E15A80CF5DD"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_275:*:*:*:*:*:*:*:*","matchCriteriaId":"92119B14-94C5-4D3D-811E-EB7336E39F3E"},{"vulnerable":true,"criteria":"cpe:2.3:h:xerox:workcentre_275:*:*:pro:*:*:*:*:*","matchCriteriaId":"2DC671C6-7444-4E3D-ACAB-8905A0DB40CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"825","Ordinal":"1","Title":"CVE-2006-0825","CVE":"CVE-2006-0825","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"825","Ordinal":"1","NoteData":"Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain \"unauthorized network access\" via unknown attack vectors.","Type":"Description","Title":"CVE-2006-0825"},{"CveYear":"2006","CveId":"825","Ordinal":"2","NoteData":"2006-02-21","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"825","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}