ID

VAR-E-201203-0962


TITLE

Multiple Xerox Devices Multiple Remote Code Execution Vulnerabilities

Trust: 0.3

sources: BID: 52483

DESCRIPTION

Multiple Xerox devices are prone to multiple remote code-execution vulnerabilities.
An attacker can exploit these issues to execute arbitrary code in the context of the affected application. Successful exploitation can completely compromise the vulnerable device.

Trust: 0.3

sources: BID: 52483

AFFECTED PRODUCTS

vendor:xeroxmodel:workcentre pro colorscope:eqversion:3545

Trust: 0.3

vendor:xeroxmodel:workcentre pro colorscope:eqversion:2636

Trust: 0.3

vendor:xeroxmodel:workcentre pro colorscope:eqversion:2128

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:90

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:75

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:65

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:55

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:45

Trust: 0.3

vendor:xeroxmodel:workcentre pro colorscope:eqversion:40

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:35

Trust: 0.3

vendor:xeroxmodel:workcentre pro colorscope:eqversion:32

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:2750

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:2550

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:2450

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:2380

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:175

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:165

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:265

Trust: 0.3

vendor:xeroxmodel:workcentre proscope:eqversion:232

Trust: 0.3

vendor:xeroxmodel:workcentre m55scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre m45scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre m35scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre m175scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre m165scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre bookmarkscope:eqversion:55

Trust: 0.3

vendor:xeroxmodel:workcentre bookmarkscope:eqversion:40

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:76750

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:76650

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:76550

Trust: 0.3

vendor:xeroxmodel:workcentre m20iscope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentre m20scope: - version: -

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7775

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7765

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7755

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7556

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7545

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7535

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7530

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7525

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7435

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7428

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7425

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7346

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7345

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7335

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7328

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7245

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7242

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7235

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7232

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7228

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7132

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7125

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:7120

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:6400

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5675

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5665

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5655

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5645

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5638

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5632

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5335

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5330

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5325

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5230

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5225

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5222

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5150

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5135

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5050

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:5030

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:4260

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:4250

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:4150

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:4118

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:3550

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:3220

Trust: 0.3

vendor:xeroxmodel:workcentrescope:eqversion:3210

Trust: 0.3

vendor:xeroxmodel:phaser 8860mfpscope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:88600

Trust: 0.3

vendor:xeroxmodel:phaser 8560mfpscope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:85600

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:85500

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:78000

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:77600

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:75000

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:74000

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:63600

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:63500

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:55500

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:46200

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:46000

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:45100

Trust: 0.3

vendor:xeroxmodel:phaser 3635mfpscope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:36000

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:34350

Trust: 0.3

vendor:xeroxmodel:phaser 3300mfpscope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:phaserscope:eqversion:32500

Trust: 0.3

vendor:xeroxmodel:phaser 3160nscope:eqversion:0

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9303

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9302

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9301

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9203

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9202

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:9201

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:8870

Trust: 0.3

vendor:xeroxmodel:colorqubescope:eqversion:8570

Trust: 0.3

sources: BID: 52483

EXPLOIT

The following metasploit module is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/52483.rb">/data/vulnerabilities/exploits/52483.rb</a></li>

Trust: 0.3

sources: BID: 52483

PRICE

Free

Trust: 0.3

sources: BID: 52483

TYPE

Boundary Condition Error

Trust: 0.3

sources: BID: 52483

CREDITS

The vendor reported these issues.

Trust: 0.3

sources: BID: 52483

EXTERNAL IDS

db:BIDid:52483

Trust: 0.3

sources: BID: 52483

REFERENCES

url:http://seclists.org/fulldisclosure/2016/apr/91

Trust: 0.3

url:http://h.foofus.net/goons/percx/xerox_hack.pdf

Trust: 0.3

url:http://www.xerox.com/download/security/security-bulletin/1284332-2ddc5-4baa79b70ac40/cert_xrx12-003_v1.1.pdf

Trust: 0.3

url:https://www.rapid7.com/db/modules/exploit/unix/misc/xerox_mfp

Trust: 0.3

url:http://www.xerox.com

Trust: 0.3

sources: BID: 52483

SOURCES

db:BIDid:52483

LAST UPDATE DATE

2022-07-27T09:59:01.958000+00:00


SOURCES UPDATE DATE

db:BIDid:52483date:2016-07-06T14:33:00

SOURCES RELEASE DATE

db:BIDid:52483date:2012-03-14T00:00:00