CVE-2024-55925
Last modified
CVE-2024-55925 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Workplace Suite | < 5.6.701.9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55925?
How severe is CVE-2024-55925?
How do I fix CVE-2024-55925?
Are you affected by CVE-2024-55925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
