← Back to browse · API

CVE-2019-10880

Severity
CRITICAL
CVSS
9.8
EPSS
0.08468
Risk score
42.16
CISA KEV
No
PoC
No
Published
2019-04-12
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-2602, GHSA-CP66-C3R7-36C5
Products
XEROX:ColorQube 8700/8900 unspecified <072.xxx.009.07200, XEROX:ColorQube 9301/9302/9303 unspecified <072.xxx.009.07200
Sources
euvd EUVD-2019-2602

Description

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

References