CVE-2019-18630

HIGH

Xerox AltaLink B80xx/C80xx Firmware < 101.00x.099.28200 - Cleartext Storage of Sensitive Information

Title source: llm
STIX 2.1

Description

On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.

Scores

CVSS v3 7.5
EPSS 0.0068
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (10)
xerox/altalink_b8045_firmware < 103.008.010.14010
xerox/altalink_b8055_firmware < 103.008.010.14010
xerox/altalink_b8065_firmware < 103.008.010.14010
xerox/altalink_b8075_firmware < 103.008.010.14010
xerox/altalink_b8090_firmware < 103.008.010.14010
xerox/altalink_c8030_firmware < 103.001.010.14010
xerox/altalink_c8035_firmware < 103.001.010.14010
xerox/altalink_c8045_firmware < 103.002.010.14010
xerox/altalink_c8055_firmware < 103.002.010.14010
xerox/altalink_c8070_firmware < 103.003.010.14010
Published Mar 04, 2021
Tracked Since Feb 18, 2026