CVE Feed

    Dashboard / CVE / CVE-2021-28671

    CVE-2021-28671

    Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610 before 32.65.51 and 32.59.01 (Bridge), B605/B615 before 33.65.51 and 33.59.01 (Bridge), B7025/30/35 before 58.65.51 and 58.59.11 (Bridge), C400 before 67.65.51 and 67.59.01 (Bridge), C405 before 68.65.51 and 68.59.01 (Bridge), C500/C600 before 61.65.51 and 61.59.01 (Bridge), C505/C605 before 62.65.51 and 62.59.01 (Bridge), C7000 before 56.65.51 and 56.59.01 (Bridge), C7020/25/30 before 57.65.51 and 57.59.01 (Bridge), C8000/C9000 before 70.65.51 and 70.59.01 (Bridge), C8000W before 72.65.51 have a remote Command Execution vulnerability in the Web User Interface that allows remote attackers with "a weaponized clone file" to execute arbitrary commands.

    Published:Mar 29, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 29, 2021
    EPSS Score:0.01575
    CVSS Score:9.8

    Affected Products

    Vendor
    Xerox
    Product
    Phaser 6510
    Vendor
    Xerox
    Product
    Phaser 6510 Firmware
    Vendor
    Xerox
    Product
    Versalink B400
    Vendor
    Xerox
    Product
    Versalink B400 Firmware
    Vendor
    Xerox
    Product
    Versalink B405
    Vendor
    Xerox
    Product
    Versalink B405 Firmware
    Vendor
    Xerox
    Product
    Versalink B600
    Vendor
    Xerox
    Product
    Versalink B600 Firmware
    Vendor
    Xerox
    Product
    Versalink B605
    Vendor
    Xerox
    Product
    Versalink B605 Firmware
    Vendor
    Xerox
    Product
    Versalink B610
    Vendor
    Xerox
    Product
    Versalink B610 Firmware
    Vendor
    Xerox
    Product
    Versalink B615
    Vendor
    Xerox
    Product
    Versalink B615 Firmware
    Vendor
    Xerox
    Product
    Versalink B7025
    Vendor
    Xerox
    Product
    Versalink B7025 Firmware
    Vendor
    Xerox
    Product
    Versalink B7030
    Vendor
    Xerox
    Product
    Versalink B7030 Firmware
    Vendor
    Xerox
    Product
    Versalink B7035
    Vendor
    Xerox
    Product
    Versalink B7035 Firmware
    Vendor
    Xerox
    Product
    Versalink C400
    Vendor
    Xerox
    Product
    Versalink C400 Firmware
    Vendor
    Xerox
    Product
    Versalink C405
    Vendor
    Xerox
    Product
    Versalink C405 Firmware
    Vendor
    Xerox
    Product
    Versalink C500
    Vendor
    Xerox
    Product
    Versalink C500 Firmware
    Vendor
    Xerox
    Product
    Versalink C505
    Vendor
    Xerox
    Product
    Versalink C505 Firmware
    Vendor
    Xerox
    Product
    Versalink C600
    Vendor
    Xerox
    Product
    Versalink C600 Firmware
    Vendor
    Xerox
    Product
    Versalink C605
    Vendor
    Xerox
    Product
    Versalink C605 Firmware
    Vendor
    Xerox
    Product
    Versalink C7000
    Vendor
    Xerox
    Product
    Versalink C7000 Firmware
    Vendor
    Xerox
    Product
    Versalink C7020
    Vendor
    Xerox
    Product
    Versalink C7020 Firmware
    Vendor
    Xerox
    Product
    Versalink C7025
    Vendor
    Xerox
    Product
    Versalink C7025 Firmware
    Vendor
    Xerox
    Product
    Versalink C7030
    Vendor
    Xerox
    Product
    Versalink C7030 Firmware
    Vendor
    Xerox
    Product
    Versalink C8000
    Vendor
    Xerox
    Product
    Versalink C8000 Firmware
    Vendor
    Xerox
    Product
    Versalink C8000w
    Vendor
    Xerox
    Product
    Versalink C8000w Firmware
    Vendor
    Xerox
    Product
    Versalink C9000
    Vendor
    Xerox
    Product
    Versalink C9000 Firmware
    Vendor
    Xerox
    Product
    Workcentre 6515
    Vendor
    Xerox
    Product
    Workcentre 6515 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High