Learn about CVE-2018-17172 affecting Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices. Find out how to mitigate the unauthorized command injection vulnerability.
Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices are vulnerable to unauthorized command injection.
Understanding CVE-2018-17172
This CVE describes a vulnerability in Xerox AltaLink devices that allows unauthenticated command injection.
What is CVE-2018-17172?
The web application on Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices before specific versions is susceptible to unauthorized command injection.
The Impact of CVE-2018-17172
This vulnerability could be exploited by attackers to execute unauthorized commands on the affected devices, potentially leading to unauthorized access or control.
Technical Details of CVE-2018-17172
Xerox AltaLink devices are affected by a vulnerability that allows unauthenticated command injection.
Vulnerability Description
The web application on Xerox AltaLink B80xx, C8030/C8035, C8045/C8055, and C8070 devices before certain versions permits unauthenticated command injection.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability to inject unauthorized commands into the web application of the affected Xerox AltaLink devices.
Mitigation and Prevention
To address CVE-2018-17172, follow these steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates