CVE-2024-55925
Last modified
CVE-2024-55925 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the server improperly validates or trusts the Host header without verifying the actual destination, an attacker can forge a value to gain unauthorized access. This exploit targets improper host validation, potentially exposing sensitive API endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Workplace Suite | < 5.6.701.9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55925?
How severe is CVE-2024-55925?
How do I fix CVE-2024-55925?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55918An issue was discovered in the Graphics::ColorNames package …5.3
- CVE-2024-55920TYPO3 is a free and open source Content Management Framework…4.3
- CVE-2024-55921TYPO3 is a free and open source Content Management Framework…8.8
- CVE-2024-55922TYPO3 is a free and open source Content Management Framework…5.4
- CVE-2024-55923TYPO3 is a free and open source Content Management Framework…4.3
- CVE-2024-55924TYPO3 is a free and open source Content Management Framework…8
- CVE-2024-55926A vulnerability found in Xerox Workplace Suite allows arbitr…9.8
- CVE-2024-55927A vulnerability in Xerox Workplace Suite arises from flawed …7.5
- CVE-2024-55928Xerox Workplace Suite exposes sensitive secrets in clear tex…7.5
- CVE-2024-55929A mail spoofing vulnerability in Xerox Workplace Suite allow…5.3
- CVE-2024-55930Xerox Workplace Suite has weak default folder permissions th…9.8
- CVE-2024-55931Xerox Workplace Suite stores tokens in session storage, whic…6.5
Are you affected by CVE-2024-55925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
