CVE-2024-12510

MEDIUM

Xerox VersaLink, Phaser, and WorkCentre - LDAP Authentication Redirect Credential Exposure

Title source: manual
STIX 2.1

Description

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

Scores

CVSS v3 6.7
EPSS 0.0092
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (17)
Xerox/Phaser 6510 < 64.75.53
Xerox/Versalink B400 < 37.82.53
Xerox/Versalink B405 < 38.82.53
Xerox/Versalink B600/B610 < 32.82.53
Xerox/Versalink B605/B615 < 33.82.53
Xerox/Versalink B7025/B7030/B7035 < 58.75.53
Xerox/Versalink B7125/B7130/B7135 < 59.24.53
Xerox/Versalink C400 < 67.82.53
Xerox/Versalink C405 < 68.82.53
Xerox/Versalink C500/C600 < 61.82.53
... and 7 more
Published Feb 03, 2025
Tracked Since Feb 18, 2026