Vulnerability Name:

CVE-2006-1139 (CCN-25176)

Assigned:2006-03-06
Published:2006-03-06
Updated:2018-10-04
Summary:Unspecified vulnerability in the ESS/ Network Controller in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, causes the Immediate Image Overwrite feature to fail after a power loss, which could leave data exposed to attack.
CVSS v3 Severity:5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
3.6 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2006-1139

Source: CCN
Type: SA19146
Xerox CopyCentre / WorkCentre Pro Multiple Denial of Service Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
19146

Source: CCN
Type: SECTRACK ID: 1015738
Xerox WorkCentre Pro Multiple PostScript Processing Errors Let Remote Users Deny Service

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1015738

Source: OSVDB
Type: Broken Link
23728

Source: CCN
Type: OSVDB ID: 23728
XEROX CopyCentre/WorkCentre ESS/Network Controller Immediate Image Overwrite Failure Issue

Source: VUPEN
Type: Permissions Required, Third Party Advisory
ADV-2006-0857

Source: CCN
Type: XEROX SECURITY BULLETIN XRX06-002
System software versions available to address denial of service and other vulnerabilities in ESS

Source: CONFIRM
Type: Broken Link, Vendor Advisory
http://www.xerox.com/downloads/usa/en/c/cert_XRX06_002.pdf

Source: XF
Type: Third Party Advisory, VDB Entry
xerox-image-overwrite-dos(25176)

Source: XF
Type: UNKNOWN
xerox-image-overwrite-dos(25176)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xerox:copycentre_c65_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:copycentre_c65_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:copycentre_c65:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:xerox:copycentre_c75_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:copycentre_c75_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:copycentre_c75:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:xerox:copycentre_c90_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:copycentre_c90_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:copycentre_c90:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:xerox:workcentre_pro_65_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:workcentre_pro_65_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:workcentre_pro_65:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:xerox:workcentre_pro_75_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:workcentre_pro_75_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:workcentre_pro_75:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:xerox:workcentre_pro_90_firmware:*:*:*:*:*:*:*:* (Version <= 1.001.02.073)
  • OR cpe:/o:xerox:workcentre_pro_90_firmware:*:*:*:*:*:*:*:* (Version >= 1.001.02.074 and < 1.001.02.715)
  • AND
  • cpe:/h:xerox:workcentre_pro_90:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:xerox:copycentre_c65:1.001.02.0715:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:copycentre_c65:1.001.02.073:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:copycentre_c75:1.001.02.0715:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:copycentre_c75:1.001.02.073:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:copycentre_c90:1.001.02.0715:*:*:*:*:*:*:*
  • OR cpe:/h:xerox:copycentre_c90:1.001.02.073:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    xerox copycentre c65 firmware *
    xerox copycentre c65 firmware *
    xerox copycentre c65 -
    xerox copycentre c75 firmware *
    xerox copycentre c75 firmware *
    xerox copycentre c75 -
    xerox copycentre c90 firmware *
    xerox copycentre c90 firmware *
    xerox copycentre c90 -
    xerox workcentre pro 65 firmware *
    xerox workcentre pro 65 firmware *
    xerox workcentre pro 65 -
    xerox workcentre pro 75 firmware *
    xerox workcentre pro 75 firmware *
    xerox workcentre pro 75 -
    xerox workcentre pro 90 firmware *
    xerox workcentre pro 90 firmware *
    xerox workcentre pro 90 -
    xerox copycentre c65 1.001.02.0715
    xerox copycentre c65 1.001.02.073
    xerox copycentre c75 1.001.02.0715
    xerox copycentre c75 1.001.02.073
    xerox copycentre c90 1.001.02.0715
    xerox copycentre c90 1.001.02.073