SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-20770

There is Blind SQL Injection.

CRITICAL 9.8EPSS 1.06%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
xerox/workcentre 3655i firmware · xerox/workcentre 3655 firmware · xerox/workcentre 5890i firmware · xerox/workcentre 5865i firmware · xerox/workcentre 5875i firmware · xerox/workcentre 5845 firmware · xerox/workcentre 5865 firmware · xerox/workcentre 5875 firmware · xerox/workcentre 5890 firmware · xerox/workcentre 5900 firmware · xerox/workcentre 5900i firmware · xerox/workcentre 6655 firmware · xerox/workcentre 6655i firmware · xerox/workcentre 7855 firmware · xerox/workcentre 7225 firmware · xerox/workcentre 7220 firmware · xerox/workcentre 7220i firmware · xerox/workcentre 7225i firmware · xerox/workcentre 7855i firmware · xerox/workcentre 7845i firmware · +9 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.