CVE Published: 12/04/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: airbus |
Vendor: XEROX |
Product: AltaLink B8045/B8055/B8065/B8075/B8090 Status : PUBLISHED
CVE-2019-10880 Description
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.