CVE-2018-20768 is a critical vulnerability affecting various Xerox WorkCentre devices, including models 3655, 58XX, 59XX, 6655, 72XX, 78XX, 7970, and EC78XX, specifically those running firmware versions prior to R18-05 073.xxx.0487.15000. This flaw allows an unauthenticated attacker to execute arbitrary PHP code due to a writable file, posing a severe risk to the confidentiality, integrity, and availability of affected systems. With a CVSS v3 score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. Despite its high severity, there is no evidence of active exploitation, publicly available exploit code in common repositories like Metasploit or ExploitDB, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 073.060.048.15000CPE matchmatch criteria | cpe:2.3:o:xerox:workcentre_3655i_firmware:*:*:*:*:*:*:*:* | ||
< 073.060.048.15000CPE matchmatch criteria | cpe:2.3:o:xerox:workcentre_3655_firmware:*:*:*:*:*:*:*:* | ||
< 073.190.048.15000CPE matchmatch criteria | cpe:2.3:o:xerox:workcentre_5890i_firmware:*:*:*:*:*:*:*:* | ||
< 073.190.048.15000CPE matchmatch criteria | cpe:2.3:o:xerox:workcentre_5865i_firmware:*:*:*:*:*:*:*:* | ||
< 073.190.048.15000CPE matchmatch criteria | cpe:2.3:o:xerox:workcentre_5875i_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.