Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

BID:14586

Info

Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

Bugtraq ID: 14586
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Aug 17 2005 12:00AM
Updated: Aug 17 2005 12:00AM
Credit: The vendor announced these vulnerabilities.
Vulnerable: Xerox Document Centre 555
Xerox Document Centre 545
Xerox Document Centre 535
Xerox Document Centre 490 ST
Xerox Document Centre 490
Xerox Document Centre 480 ST
Xerox Document Centre 480 DC
Xerox Document Centre 480
Xerox Document Centre 470 ST
Xerox Document Centre 470
Xerox Document Centre 460 ST
Xerox Document Centre 460
Xerox Document Centre 440 ST
Xerox Document Centre 440 DC
Xerox Document Centre 440
Xerox Document Centre 432 ST
Xerox Document Centre 432
Xerox Document Centre 430
Xerox Document Centre 426
Xerox Document Centre 425 ST
Xerox Document Centre 425
Xerox Document Centre 420 ST
Xerox Document Centre 420
Xerox Document Centre 265 ST
Xerox Document Centre 265
Xerox Document Centre 255 ST
Xerox Document Centre 255
Xerox Document Centre 240 ST
Xerox Document Centre 240
Xerox Document Centre 232
Xerox Document Centre 230 ST
Xerox Document Centre 230
Xerox Document Centre 220 ST
Xerox Document Centre 220
Not Vulnerable:

Discussion

Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

Xerox MicroServer Web Server is affected by multiple authentication bypass and input validation vulnerabilities. These issues are most likely due to a failure in the application to properly validate user-supplied input.

Successful exploitation of these vulnerabilities may lead to privilege escalation; other attacks are also possible.

Exploit / POC

Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

No exploit is required.

Solution / Fix

Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

Solution:
Xerox has released patches addressing these issues:


Xerox Document Centre 440 DC

Xerox Document Centre 470 ST

Xerox Document Centre 230

Xerox Document Centre 255 ST

Xerox Document Centre 265

Xerox Document Centre 232

Xerox Document Centre 470

Xerox Document Centre 545

Xerox Document Centre 440

Xerox Document Centre 490

Xerox Document Centre 265 ST

Xerox Document Centre 490 ST

Xerox Document Centre 460

Xerox Document Centre 480 DC

Xerox Document Centre 440 ST

Xerox Document Centre 230 ST

Xerox Document Centre 240

Xerox Document Centre 432

Xerox Document Centre 420 ST

Xerox Document Centre 460 ST

Xerox Document Centre 535

Xerox Document Centre 255

Xerox Document Centre 432 ST

Xerox Document Centre 555

Xerox Document Centre 220 ST

Xerox Document Centre 430

Xerox Document Centre 425 ST

Xerox Document Centre 426

Xerox Document Centre 420

Xerox Document Centre 425

Xerox Document Centre 480 ST

Xerox Document Centre 240 ST

Xerox Document Centre 220

Xerox Document Centre 480

References

Xerox MicroServer Web Server Multiple Authentication Bypass and Input Validation Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report