Back

CVE-2019-10880

CRITICAL

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Published: Apr 12, 2019 Modified: Jun 17, 2026
CWE-78 CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
xerox colorqube_8700_firmware * < 072.161.009.07200
xerox colorqube_8900_firmware * < 072.161.009.07200
xerox colorqube_9301_firmware * < 072.180.009.07200
xerox colorqube_9302_firmware * < 072.180.009.07200
xerox colorqube_9303_firmware * < 072.180.009.07200

GitHub Security Advisory GHSA-cp66-c3r7-36c5

Within multiple XEROX products a vulnerability allows remote command execution on the Linux...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 8.47%

Top 5% most likely to be exploited

Threat Score 41.7 / 100

Data Sources

NVD EPSS GitHub