Vulnerabilities > CVE-2006-6430 - Multiple vulnerability in Xerox WorkCentre and WorkCentre Pro

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
xerox
nessus

Summary

Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.

Nessus

NASL familyMisc.
NASL idXEROX_XRX06_006.NASL
descriptionAccording to its model number and software version, the remote host is a Xerox WorkCentre device that reportedly suffers from multiple issues such as command injection and information disclosure vulnerabilities.
last seen2020-06-01
modified2020-06-02
plugin id23751
published2006-12-01
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/23751
titleXerox WorkCentre Multiple Vulnerabilities (XRX06-006)