PT-2025-3154 · Xerox · Xerox Workplace Suite

Published

2025-01-23

·

Updated

2026-02-28

·

CVE-2024-55926

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xerox Workplace Suite versions prior to 5.6.701.9
Description A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data.
Recommendations For versions prior to 5.6.701.9, update to version 5.6.701.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation. Avoid using crafted headers until the issue is resolved.

Fix

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-01852
CVE-2024-55926

Affected Products

Xerox Workplace Suite