Xerox Multiple Product Arbitrary Command Execution Vulnerability

BID:20334

CVE-2006-5290 |

Info

Xerox Multiple Product Arbitrary Command Execution Vulnerability

Bugtraq ID: 20334
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Oct 04 2006 12:00AM
Updated: Nov 30 2006 05:44PM
Credit: Bredan O'Conner is credited with the discovery of this vulnerability.
Vulnerable: Xerox WorkCentre Pro Color 3545
Xerox WorkCentre Pro Color 2636
Xerox WorkCentre Pro Color 2128
Xerox WorkCentre Pro 90
Xerox WorkCentre Pro 75
Xerox WorkCentre Pro 65
Xerox WorkCentre Pro 55
Xerox WorkCentre Pro 45
Xerox WorkCentre Pro 40 Color
Xerox WorkCentre Pro 35
Xerox WorkCentre Pro 32 Color
Xerox WorkCentre Pro 175
Xerox WorkCentre Pro 165
Xerox WorkCentre Pro 275
Xerox WorkCentre Pro 265
Xerox WorkCentre Pro 255
Xerox WorkCentre Pro 245
Xerox WorkCentre Pro 238
Xerox WorkCentre Pro 232
Xerox WorkCentre M55
Xerox WorkCentre M45
Xerox WorkCentre M35
Xerox WorkCentre M175
Xerox WorkCentre M165
Xerox WorkCentre 275
Xerox WorkCentre 265
Xerox WorkCentre 255
Xerox WorkCentre 245
Xerox WorkCentre 238
Xerox WorkCentre 232
Xerox Document Centre 555
Xerox Document Centre 545
Xerox Document Centre 535
Xerox Document Centre 490
Xerox Document Centre 480
Xerox Document Centre 470
Xerox Document Centre 460
Xerox Document Centre 440
Xerox Document Centre 432
Xerox Document Centre 430
Xerox Document Centre 426
Xerox Document Centre 425
Xerox Document Centre 420
Xerox Document Centre 340
Xerox Document Centre 332
Xerox Document Centre 265
Xerox Document Centre 255
Xerox Document Centre 240
Xerox Document Centre 230
Xerox Document Centre 220
Not Vulnerable:

Discussion

Xerox Multiple Product Arbitrary Command Execution Vulnerability

Multiple Xerox products are prone to an arbitrary-command-execution vulnerability.

An attacker can exploit this issue to bypass the authentication mechanism and execute arbitrary commands. If successful, the attacker could make unauthorized changes to the system configuration. Customer and user passwords are not exposed.

Exploit / POC

Xerox Multiple Product Arbitrary Command Execution Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]

Solution / Fix

Xerox Multiple Product Arbitrary Command Execution Vulnerability

Solution:
The vendor has released a patch to address this issue. Please see the references for more information.


Xerox WorkCentre 275

Xerox WorkCentre M165

Xerox WorkCentre Pro 90

Xerox WorkCentre M35

Xerox WorkCentre Pro 75

Xerox Document Centre 230

Xerox Document Centre 265

Xerox WorkCentre 265

Xerox WorkCentre M45

Xerox WorkCentre Pro 35

Xerox WorkCentre Pro 32 Color

Xerox Document Centre 470

Xerox WorkCentre Pro 165

Xerox WorkCentre Pro 65

Xerox Document Centre 545

Xerox WorkCentre Pro 255

Xerox Document Centre 440

Xerox Document Centre 490

Xerox WorkCentre 255

Xerox Document Centre 460

Xerox WorkCentre Pro 45

Xerox WorkCentre Pro 245

Xerox WorkCentre Pro Color 2636

Xerox Document Centre 240

Xerox WorkCentre Pro Color 3545

Xerox Document Centre 432

Xerox Document Centre 255

Xerox Document Centre 535

Xerox WorkCentre Pro 175

Xerox WorkCentre Pro 275

Xerox WorkCentre Pro 265

Xerox WorkCentre M55

Xerox WorkCentre 238

Xerox Document Centre 340

Xerox WorkCentre M175

Xerox WorkCentre 245

Xerox Document Centre 555

Xerox WorkCentre 232

Xerox Document Centre 430

Xerox WorkCentre Pro 238

Xerox Document Centre 426

Xerox Document Centre 420

Xerox WorkCentre Pro Color 2128

Xerox Document Centre 425

Xerox Document Centre 220

Xerox WorkCentre Pro 55

Xerox Document Centre 480

Xerox WorkCentre Pro 40 Color

Xerox WorkCentre Pro 232

Xerox Document Centre 332

References

Xerox Multiple Product Arbitrary Command Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report