Vulnerabilities > CVE-2021-28669 - Missing Authorization vulnerability in Xerox products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
xerox
CWE-862

Summary

Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without administrative rights.

Vulnerable Configurations

Part Description Count
OS
Xerox
31
Hardware
Xerox
10

Common Weakness Enumeration (CWE)