PT-2018-13696 · Fuji Xerox · Fuji Xerox Docucentre-V 3065+7
Published
2018-09-07
·
Updated
2019-10-03
·
CVE-2018-16709
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Fuji Xerox DocuCentre-V 3065
ApeosPort-VI C3371
ApeosPort-V C4475
ApeosPort-V C3375
DocuCentre-VI C2271
ApeosPort-V C5576
DocuCentre-IV C2263
DocuCentre-V C2263
ApeosPort-V 5070
Description
The issue allows remote attackers to read or write to files by sending crafted PJL commands.
Recommendations
For Fuji Xerox DocuCentre-V 3065, consider restricting access to the PJL command interface until a patch is available.
For ApeosPort-VI C3371, restrict access to the PJL command interface to minimize the risk of exploitation.
For ApeosPort-V C4475, disable the PJL command interface as a temporary workaround.
For ApeosPort-V C3375, avoid using the PJL command interface in untrusted networks.
For DocuCentre-VI C2271, limit access to the PJL command interface.
For ApeosPort-V C5576, restrict the use of the PJL command interface.
For DocuCentre-IV C2263, consider disabling the PJL command interface.
For DocuCentre-V C2263, restrict access to the PJL command interface.
For ApeosPort-V 5070, limit the use of the PJL command interface.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apeosport-V 5070
Apeosport-V C3375
Apeosport-V C4475
Apeosport-V C5576
Apeosport-Vi C3371
Docucentre-Iv C2263
Docucentre-Vi C2271
Fuji Xerox Docucentre-V 3065