Back
CVE-2019-10880
CRITICAL
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Published: Apr 12, 2019
Modified: Jun 17, 2026
CWE-78
CWE-78
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| xerox | colorqube_8700_firmware | * < 072.161.009.07200 |
| xerox | colorqube_8900_firmware | * < 072.161.009.07200 |
| xerox | colorqube_9301_firmware | * < 072.180.009.07200 |
| xerox | colorqube_9302_firmware | * < 072.180.009.07200 |
| xerox | colorqube_9303_firmware | * < 072.180.009.07200 |
GitHub Security Advisory GHSA-cp66-c3r7-36c5
Within multiple XEROX products a vulnerability allows remote command execution on the Linux...
References (4)
- https://airbus-seclab.github.io/ Not Applicable
- https://securitydocs.business.xerox.com/wp-content/uploads/2019/04/cert_Security_Mini_Bulletin_XRX19C_for_CQ8700_CQ8900_CQ93xx.pdf Vendor Advisory
- https://airbus-seclab.github.io/ Not Applicable
- https://securitydocs.business.xerox.com/wp-content/uploads/2019/04/cert_Security_Mini_Bulletin_XRX19C_for_CQ8700_CQ8900_CQ93xx.pdf Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
8.47%
Top 5% most likely to be exploited
Threat Score
41.7 / 100
Data Sources
NVD
EPSS
GitHub