Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
BID:36177
Info
Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
| Bugtraq ID: | 36177 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2009 12:00AM |
| Updated: | Jan 22 2010 04:01PM |
| Credit: | Xerox |
| Vulnerable: |
Xerox WorkCentre 7675 Xerox WorkCentre 7665 Xerox WorkCentre 7655 Xerox WorkCentre 6400 Xerox WorkCentre 5687 Xerox WorkCentre 5675 Xerox WorkCentre 5665 Xerox WorkCentre 5655 Xerox WorkCentre 5645 Xerox WorkCentre 5638 Xerox WorkCentre 5632 Xerox WorkCentre 5150 Xerox WorkCentre 5135 Xerox WorkCentre 5050 Xerox WorkCentre 5030 Xerox ColorQube 9203 Xerox ColorQube 9202 Xerox ColorQube 9201 |
| Not Vulnerable: | |
Discussion
Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
Xerox WorkCentre is prone to a vulnerability that can result in unauthorized access.
A remote attacker can exploit this issue to gain unauthorized access to the device's configuration settings and possibly customer passwords.
Xerox WorkCentre is prone to a vulnerability that can result in unauthorized access.
A remote attacker can exploit this issue to gain unauthorized access to the device's configuration settings and possibly customer passwords.
Exploit / POC
Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
Solution:
The vendor has released an advisory and a patch. Please see the references for details.
Xerox WorkCentre 5687
Xerox WorkCentre 5655
Xerox WorkCentre 5638
Xerox WorkCentre 5645
Xerox WorkCentre 5665
Xerox WorkCentre 5675
Solution:
The vendor has released an advisory and a patch. Please see the references for details.
Xerox WorkCentre 5687
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
Xerox WorkCentre 5655
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
Xerox WorkCentre 5638
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
Xerox WorkCentre 5645
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
Xerox WorkCentre 5665
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
Xerox WorkCentre 5675
-
Xerox cert_P39v2_WC56xx08_Patch.zip
http://www.xerox.com/downloads/usa/en/c/cert_P39v2_WC56xx08_Patch.zip
References
Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
References:
References:
- Xerox Homepage (Xerox)
- Xerox Security Bulletin XRX09-003 Version 1.2 (Xerox)
- Xerox Security Bulletin XRX09-003 (Xerox)