VulnerabilityModified
CVE-2018-20768
An attacker can execute PHP code by leveraging a writable file.
CRITICAL 9.8EPSS 1.23%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- xerox/workcentre 3655i firmware · xerox/workcentre 3655 firmware · xerox/workcentre 5890i firmware · xerox/workcentre 5865i firmware · xerox/workcentre 5875i firmware · xerox/workcentre 5845 firmware · xerox/workcentre 5865 firmware · xerox/workcentre 5875 firmware · xerox/workcentre 5890 firmware · xerox/workcentre 5900 firmware · xerox/workcentre 5900i firmware · xerox/workcentre 6655 firmware · xerox/workcentre 6655i firmware · xerox/workcentre 7855 firmware · xerox/workcentre 7225 firmware · xerox/workcentre 7220 firmware · xerox/workcentre 7220i firmware · xerox/workcentre 7225i firmware · xerox/workcentre 7855i firmware · xerox/workcentre 7845i firmware · +9 more
- Source
- cve@mitre.org
References
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_Security_Mini_Bulletin_XRX18Y_for_ConnectKey_EC78xx_v1.0.pdfPatch, Vendor Advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2018/07/cert_Security_Mini_Bulletin_XRX18Y_for_ConnectKey_EC78xx_v1.0.pdfPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.