Vulnerabilities

Summary — last 7 days

New vulnerabilities3,007▼ 67 vs. last week
Critical / high1,403▲ 50 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)390▼ 120 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)0.80%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+261/26/20216/17/2026
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
ModifiedCritical (9.8)2.0%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5865 FirmwareXerox Workcentre 5875 Firmware+214/29/20206/17/2026
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
ModifiedHigh (8.8)1.1%—Xerox Workcentre 3655 FirmwareXerox Workcentre 3655i FirmwareXerox Workcentre 5845 FirmwareXerox Workcentre 5855 Firmware+142/21/20206/17/2026
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system…
ModifiedCritical (9.8)3.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+252/10/20196/17/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.
ModifiedCritical (9.8)1.1%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+252/10/20196/17/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
ModifiedHigh (7.5)1.4%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+252/10/20196/17/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
ModifiedCritical (9.8)1.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+252/10/20196/17/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
ModifiedHigh (8.8)2.2%—Xerox Workcentre 3655i FirmwareXerox Workcentre 3655 FirmwareXerox Workcentre 5890i FirmwareXerox Workcentre 5865i Firmware+252/10/20196/17/2026
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.