SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-20769

There is a Local File Inclusion vulnerability.

HIGH 7.5EPSS 1.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
xerox/workcentre 3655i firmware · xerox/workcentre 3655 firmware · xerox/workcentre 5890i firmware · xerox/workcentre 5865i firmware · xerox/workcentre 5875i firmware · xerox/workcentre 5845 firmware · xerox/workcentre 5865 firmware · xerox/workcentre 5875 firmware · xerox/workcentre 5890 firmware · xerox/workcentre 5900 firmware · xerox/workcentre 5900i firmware · xerox/workcentre 6655 firmware · xerox/workcentre 6655i firmware · xerox/workcentre 7855 firmware · xerox/workcentre 7225 firmware · xerox/workcentre 7220 firmware · xerox/workcentre 7220i firmware · xerox/workcentre 7225i firmware · xerox/workcentre 7855i firmware · xerox/workcentre 7845i firmware · +9 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.