Fuji Xerox's vulnerability footprint centers on a compact range of document-imaging and printing devices, including the DocuPrint series network-enabled multifunction systems. The durable signal is concentrated in network-option and authentication components across these embedded devices, where improper authentication mechanisms recur as a structural weakness class.
The number and severity of CVEs published that impact products developed by Fuji Xerox over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16709CRITICAL Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPo | Sep 7, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-5520HIGH The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati | Jan 27, 2020 | 7.4 | 24 | NO | NO |
CVE-2020-5521HIGH The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in | Jan 27, 2020 | 7.4 | 23 | NO | NO |
CVE-2017-10851HIGH Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspeci | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-10849HIGH Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecif | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-10848HIGH Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published in Jul 2017 and earlier allows an attacker to gain privileges | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2021-20679HIGH Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C33 | Mar 25, 2021 | 7.5 | 21 | NO | NO |
CVE-2019-16307MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allow | Sep 14, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-6004MEDIUM Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect user | Sep 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-5526MEDIUM The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers | Jan 31, 2020 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fuji Xerox.
Media articles that mention a CVE ID that affects a product developed by Fuji Xerox — matched by CVE ID, not by vendor name.