« Volver al listado

CVE-2024-55931

Estado: AnalizadaMedia (6.5)—

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.

The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-55931",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-55931",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-27T13:26:58.343505Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "10b61619-3869-496c-8a1e-f291b0e71e3f",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "10b61619-3869-496c-8a1e-f291b0e71e3f",
      "affectedData": [
        {
          "vendor": "Xerox",
          "product": "Xerox Workplace Suite",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.6.701.9",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-01-27T12:15:27.407",
  "references": [
    {
      "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "10b61619-3869-496c-8a1e-f291b0e71e3f"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "10b61619-3869-496c-8a1e-f291b0e71e3f",
      "description": [
        {
          "lang": "en",
          "value": "CWE-922"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. \n\nThe patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin."
    },
    {
      "lang": "es",
      "value": "Xerox Workplace Suite almacena tokens en el almacenamiento de sesiones, lo que puede exponerlos a un posible acceso si la sesión de un usuario se ve comprometida. El parche para esta vulnerabilidad se incluirá en una versión futura de Workplace Suite y se notificará a los clientes mediante una actualización del boletín de seguridad."
    }
  ],
  "lastModified": "2026-06-17T08:11:28.337",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xerox:workplace_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EF146CA-62DE-40D4-B12B-EEA46618D8AF",
              "versionEndExcluding": "5.6.701.9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "10b61619-3869-496c-8a1e-f291b0e71e3f"
}