Vulnerability Name:

CVE-2005-2645 (CCN-21889)

Assigned:2005-08-10
Published:2005-08-10
Updated:2008-09-05
Summary:Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to bypass authentication.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2005-2645

Source: CCN
Type: SA16467
Xerox Document Centre MicroServer Web Server Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
16467

Source: CCN
Type: SECTRACK ID: 1014720
Xerox Document Centre MicroServer Web Server Bugs Let Remote Users Bypass Authentication, View Files, and Deny Service

Source: SECTRACK
Type: UNKNOWN
1014720

Source: CCN
Type: Document Centre 426 Copier-Printer 426 Web site
Xerrox Office - Document Centre 426 Multifunction copier-printer offers unparalleled functionality and flexibility

Source: CCN
Type: XEROX Security Bulletin XRX05-008
Vulnerabilities in the Xeros MicroServer Web Server could potentially permit unauthorized access.

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.xerox.com/downloads/usa/en/c/cert_XRX05_008.pdf

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.xerox.com/downloads/usa/en/c/cert_XRX05_009.pdf

Source: XF
Type: UNKNOWN
xerox-documentcentre-auth-bypass(21889)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:xerox:document_centre_265:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_332:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_340:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_420:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_490:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_535:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_555:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:xerox:document_centre_470:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_430:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_425:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_240:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_265:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_420:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_426:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_440:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_460:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_480:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_490:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_535:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_545:*:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:document_centre_555:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    xerox document centre 265 *
    xerox document centre 332 *
    xerox document centre 340 *
    xerox document centre 420 *
    xerox document centre 490 *
    xerox document centre 535 *
    xerox document centre 555 *
    xerox document centre 470 *
    xerox document centre 430 *
    xerox document centre 425 *
    xerox document centre 240 *
    xerox document centre 265 *
    xerox document centre 420 *
    xerox document centre 426 *
    xerox document centre 440 *
    xerox document centre 460 *
    xerox document centre 480 *
    xerox document centre 490 *
    xerox document centre 535 *
    xerox document centre 545 *
    xerox document centre 555 *