668
VMScore

CVE-2021-28671

Published: 29/03/2021 Updated: 05/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Xerox Phaser 6510 prior to 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 prior to 65.65.51 and 65.59.11 (Bridge), VersaLink B400 prior to 37.65.51 and 37.59.01 (Bridge), B405 prior to 38.65.51 and 38.59.01 (Bridge), B600/B610 prior to 32.65.51 and 32.59.01 (Bridge), B605/B615 prior to 33.65.51 and 33.59.01 (Bridge), B7025/30/35 prior to 58.65.51 and 58.59.11 (Bridge), C400 prior to 67.65.51 and 67.59.01 (Bridge), C405 prior to 68.65.51 and 68.59.01 (Bridge), C500/C600 prior to 61.65.51 and 61.59.01 (Bridge), C505/C605 prior to 62.65.51 and 62.59.01 (Bridge), C7000 prior to 56.65.51 and 56.59.01 (Bridge), C7020/25/30 prior to 57.65.51 and 57.59.01 (Bridge), C8000/C9000 prior to 70.65.51 and 70.59.01 (Bridge), C8000W prior to 72.65.51 have a remote Command Execution vulnerability in the Web User Interface that allows remote attackers with "a weaponized clone file" to execute arbitrary commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xerox phaser_6510_firmware

xerox workcentre_6515_firmware

xerox versalink_b400_firmware

xerox versalink_b405_firmware

xerox versalink_b600_firmware

xerox versalink_b610_firmware

xerox versalink_b605_firmware

xerox versalink_b615_firmware

xerox versalink_b7025_firmware

xerox versalink_b7030_firmware

xerox versalink_b7035_firmware

xerox versalink_c400_firmware

xerox versalink_c405_firmware

xerox versalink_c500_firmware

xerox versalink_c600_firmware

xerox versalink_c505_firmware

xerox versalink_c605_firmware

xerox versalink_c7000_firmware

xerox versalink_c7020_firmware

xerox versalink_c7025_firmware

xerox versalink_c7030_firmware

xerox versalink_c8000_firmware

xerox versalink_c9000_firmware

xerox versalink_c8000w_firmware