CVE-2019-10880 - CVE House
Back to Database
Status published Critical CVE-2019-10880

Within multiple XEROX products a vulnerability allows remote command execution...

Vulnerability Description

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10880

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Raphaël Rigo from the Airbus Security Lab

Affected Vendor

Affected Software

AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070, WorkCentre 3655, WorkCentre 5845/5855/5865/5875/5890, WorkCentre 5945/5955, WorkCentre 6655, WorkCentre 7220/7225, WorkCentre 7830/7835/7845/7855, WorkCentre 7970, WorkCentre EC7836/EC7856, ColorQube 9301/9302/9303, ColorQube 8700/8900, WorkCentre 6400, Phaser 6700, Phaser 7800, WorkCentre 5735/5740/5745/5755/5765/5775/5790, WorkCentre 7525/7530/7535/7545/7556, WorkCentre 7755/7765/7775
Vulnerable Versions:
unspecified

Timeline

Official Publish: April 12th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)