CVE-2019-18630

HIGHCVSS 7.5/10EPSS 0.68%

Last modified

CVE-2019-18630 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.

Description

On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.68%

47.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
XeroxAltalink B8045 Firmware< 103.008.010.14010
XeroxAltalink B8055 Firmware< 103.008.010.14010
XeroxAltalink B8065 Firmware< 103.008.010.14010
XeroxAltalink B8075 Firmware< 103.008.010.14010
XeroxAltalink B8090 Firmware< 103.008.010.14010
XeroxAltalink C8030 Firmware< 103.001.010.14010
XeroxAltalink C8035 Firmware< 103.001.010.14010
XeroxAltalink C8045 Firmware< 103.002.010.14010
XeroxAltalink C8055 Firmware< 103.002.010.14010
XeroxAltalink C8070 Firmware< 103.003.010.14010

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-18630?
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.
How severe is CVE-2019-18630?
CVE-2019-18630 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.68% probability of exploitation in the next 30 days.
How do I fix CVE-2019-18630?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-18630?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST