PT-2025-3153 · Xerox · Xerox Workplace Suite

Published

2025-01-23

·

Updated

2026-02-28

·

CVE-2024-55925

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xerox Workplace Suite versions prior to 5.6.701.9
Description The issue involves an API security bypass through header manipulation. In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.
Recommendations Xerox Workplace Suite versions prior to 5.6.701.9 should update to version 5.6.701.9 or later to resolve the issue.

Fix

Improper Authentication

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2025-01850
CVE-2024-55925

Affected Products

Xerox Workplace Suite