Fujixerox's vulnerability footprint centers on multifunction printers and document management systems such as its DocuPrint series and ApeosWare management suite, products that occupy a prominent but specialized position in enterprise office environments. The recurring weakness classes—improper certificate validation, untrusted search paths, and web application issues including cross-site scripting and open redirects—reflect the network connectivity and embedded web interfaces characteristic of modern office equipment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fujixerox over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16709CRITICAL Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPo | Sep 7, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-5520HIGH The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati | Jan 27, 2020 | 7.4 | 24 | NO | NO |
CVE-2020-5521HIGH The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in | Jan 27, 2020 | 7.4 | 23 | NO | NO |
CVE-2017-10851HIGH Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspeci | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-10849HIGH Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecif | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-10848HIGH Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published in Jul 2017 and earlier allows an attacker to gain privileges | Sep 1, 2017 | 7.8 | 23 | NO | NO |
CVE-2021-20679HIGH Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C33 | Mar 25, 2021 | 7.5 | 21 | NO | NO |
CVE-2019-16307MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allow | Sep 14, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-6004MEDIUM Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect user | Sep 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-5526MEDIUM The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers | Jan 31, 2020 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fujixerox.
Media articles that mention a CVE ID that affects a product developed by Fujixerox — matched by CVE ID, not by vendor name.