PT-2021-17893 · Xerox · Xerox Altalink C8045/C8055+3

Published

2021-03-29

·

Updated

2021-04-01

·

CVE-2021-28670

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xerox AltaLink B8045/B8090 versions before 103.008.030.32000 Xerox AltaLink C8030/C8035 versions before 103.001.030.32000 Xerox AltaLink C8045/C8055 versions before 103.002.030.32000 Xerox AltaLink C8070 versions before 103.003.030.32000
Description: The issue allows unauthorized users to delete arbitrary files from the disk by leveraging the Scan To Mailbox feature.
Recommendations: For Xerox AltaLink B8045/B8090 versions before 103.008.030.32000, update to version 103.008.030.32000 or later. For Xerox AltaLink C8030/C8035 versions before 103.001.030.32000, update to version 103.001.030.32000 or later. For Xerox AltaLink C8045/C8055 versions before 103.002.030.32000, update to version 103.002.030.32000 or later. For Xerox AltaLink C8070 versions before 103.003.030.32000, update to version 103.003.030.32000 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-28670

Affected Products

Xerox Altalink B8045/B8090
Xerox Altalink C8030/C8035
Xerox Altalink C8045/C8055
Xerox Altalink C8070