CVE-2019-10881 - CVE House
Back to Database
Status published Critical CVE-2019-10881

Default hidden Privileged Account Vulnerability in multiple XEROX devices

Vulnerability Description

Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10881

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Raphaël Rigo from the Airbus Security Lab

Affected Vendor

Affected Software

AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070, WorkCentre 3655, WorkCentre 5845/5855/5865/5875/5890, WorkCentre 5945/5955, WorkCentre 6655, WorkCentre 7220/7225, WorkCentre 7830/7835/7845/7855, WorkCentre 7970, WorkCentre EC7836/EC7856, ColorQube 9301/9302/9303, ColorQube 8700/8900, WorkCentre 6400, Phaser 6700, Phaser 7800, WorkCentre 5735/5740/5745/5755/5765/5775/5790, WorkCentre 7525/7530/7535/7545/7556, WorkCentre 7755/7765/7775
Vulnerable Versions:
Unknown

Timeline

Official Publish: April 13th, 2021
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Weaknesses (CWE)