« Back to list

CVE-2010-0549

Status: ModifiedMedium (5)—

Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure Access Vulnerability."

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2010-0549",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-02-04T20:15:50.030",
  "references": [
    {
      "url": "http://secunia.com/advisories/38339",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1023500",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0208",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX10-001_v1.0.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38339",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1023500",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0208",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.xerox.com/downloads/usa/en/c/cert_XRX10-001_v1.0.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access \"directory structure\" via a crafted PostScript file, aka \"Unauthorized Directory Structure Access Vulnerability.\""
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especifica en el Network Controller en Xerox WorkCentre 6400 System Software v060.070.109.11407 hasta v060.070.109.29510, y Net Controller v060.079.11410 hasta v060.079.29310, permite a atacantse remotos acceder al \"directorio de estructura\" a través de un archivo PostScript manipulado, como \"Vulnerabilidad no autorizada al Directorio de Estrucutra.\""
    }
  ],
  "lastModified": "2026-06-16T23:16:23.063",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xerox:workcentre_6400_net_controller:060.079.11410:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36E918FE-89E9-4E31-A69B-D73F2CDB9C4C"
            },
            {
              "criteria": "cpe:2.3:a:xerox:workcentre_6400_net_controller:060.079.29310:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EF53B38-8DA6-4310-B5D0-07DDC439E0BD"
            },
            {
              "criteria": "cpe:2.3:a:xerox:workcentre_6400_system_software:060.070.109.11407:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E403840E-FAD9-478B-9826-3D5FB6BE1FA7"
            },
            {
              "criteria": "cpe:2.3:a:xerox:workcentre_6400_system_software:060.070.109.29510:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C6D0E43-CC7D-4B38-886A-9A88D8134E53"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}