Vulnerabilities > CVE-2006-0825 - Local Authentication Bypass vulnerability in Xerox WorkCentre Products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
xerox
nessus

Summary

Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthorized network access" via unknown attack vectors.

Nessus

NASL familyMisc.
NASL idXEROX_XRX06_001.NASL
descriptionAccording to its model number and software version, the remote host is a Xerox WorkCentre device that reportedly is affected by several issues, including authentication bypass / unauthorized network access, denial of service when handling malformed Postscript files, an unspecified cross-site scripting issue, and unspecified errors that might reduce the effectiveness of certain security features.
last seen2020-06-01
modified2020-06-02
plugin id20951
published2006-02-21
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/20951
titleXerox WorkCentre Multiple Vulnerabilities (XRX06-001)