SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-20767

There is authenticated remote command execution.

HIGH 8.8EPSS 2.24%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
2.24% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
xerox/workcentre 3655i firmware · xerox/workcentre 3655 firmware · xerox/workcentre 5890i firmware · xerox/workcentre 5865i firmware · xerox/workcentre 5875i firmware · xerox/workcentre 5845 firmware · xerox/workcentre 5865 firmware · xerox/workcentre 5875 firmware · xerox/workcentre 5890 firmware · xerox/workcentre 5900 firmware · xerox/workcentre 5900i firmware · xerox/workcentre 6655 firmware · xerox/workcentre 6655i firmware · xerox/workcentre 7855 firmware · xerox/workcentre 7225 firmware · xerox/workcentre 7220 firmware · xerox/workcentre 7220i firmware · xerox/workcentre 7225i firmware · xerox/workcentre 7855i firmware · xerox/workcentre 7845i firmware · +9 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.