Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue."
Project Subscriptions
| Vendors | Products |
|---|---|
|
Xerox
Subscribe
|
Versalink B400
Subscribe
Versalink B405
Subscribe
Versalink B600
Subscribe
Versalink B610
Subscribe
Versalink B7025
Subscribe
Versalink B7030
Subscribe
Versalink B7035
Subscribe
Versalink C400
Subscribe
Versalink C405
Subscribe
Versalink C500
Subscribe
Versalink C505
Subscribe
Versalink C600
Subscribe
Versalink C605
Subscribe
Versalink C7000
Subscribe
Versalink C7020
Subscribe
Versalink C7025
Subscribe
Versalink C7030
Subscribe
Versalink C8000
Subscribe
Versalink C8000w
Subscribe
Versalink C9000
Subscribe
Versalink Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28884 | Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes. However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included "believed to affect all previous and later versions as of the date of this posting" but a 2022-01-26 vendor statement reports "the latest versions of firmware are not vulnerable to this issue." |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T03:59:23.128Z
Reserved: 2022-01-26T00:00:00
Link: CVE-2022-23968
No data.
Status : Modified
Published: 2022-01-26T06:15:06.843
Modified: 2024-11-21T06:49:32.480
Link: CVE-2022-23968
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD