Xerox WorkCentre Multiple OpenSSL Vulnerabilities (XRX07-001)

This script is Copyright (C) 2007-2013 Tenable Network Security, Inc.


Synopsis :

The remote multi-function device is affected by multiple issues.

Description :

According to its model number and software version, the remote host
is a Xerox WorkCentre device that reportedly suffers from multiple
issues in the ESS / Network Controller that could allow remote
execution of arbitrary code on the affected device, initiation of
denial of service attacks, and forgery of digital certificates.

See also :

http://www.nessus.org/u?99fdc232

Solution :

Apply the P30 patch as described in the Xerox security bulletin
referenced above.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 5.8
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Misc.

Nessus Plugin ID: 25637 ()

Bugtraq ID: 20246
20247
20248
20249

CVE ID: CVE-2006-2937
CVE-2006-2940
CVE-2006-3738
CVE-2006-4343