« Volver al listado

CVE-2006-6435

Estado: ModificadaAlta (7.5)—

The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which allows remote attackers to more easily gain system access and obtain sensitive information via a brute force attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6435",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-12-10T11:28:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/23265",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23265",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX06_004_v11.pdf",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which allows remote attackers to more easily gain system access and obtain sensitive information via a brute force attack."
    },
    {
      "lang": "es",
      "value": "La implementación SNMP en Xerox WorkCentre y WorkCentre Pro anterior 12.050.03.000, 13.x anterior 13.050.03.000, y 14.x anterior 14.050.03.000 no genera validación de fallos de trampa, lo cual permite a atacantes remotos, mas facilemente, ganar accesos en el sistema y obtener información sensible a través de ataques por fuerza bruta."
    }
  ],
  "lastModified": "2026-06-16T22:33:07.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:12.060.17.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF9C033D-37D1-445F-B0FC-5B388805506D"
            },
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:12.060.17.000:*:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "216F3E75-F438-4090-980E-E8E4895B7CA0"
            },
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:13.060.17.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA3716B1-3B5F-44A5-A5A2-ADA965536D02"
            },
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:13.060.17.000:*:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A2E5932-2D90-48C2-93F7-D3040F872E35"
            },
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:14.060.17.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEFAD4E9-11AC-425D-A95C-9C722177A51C"
            },
            {
              "criteria": "cpe:2.3:h:xerox:workcentre:14.060.17.000:*:pro:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EF56EDD-26FE-405B-9BAA-E5279E46FD32"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}