Xerox AltaLink Abuse Scan Feature to Delete Files (CVE-2021-28670)

critical Tenable OT Security Plugin ID 505552

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailbox feature, to delete arbitrary files from the disk.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?1b8423e5

http://www.nessus.org/u?44f1de43

Plugin Details

Severity: Critical

ID: 505552

File Name: tenable_ot_xerox_CVE-2021-28670.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/27/2026

Updated: 7/27/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.06

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2021-28670

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Vulnerability Information

CPE: cpe:/o:xerox:altalink_b8045_firmware, cpe:/o:xerox:altalink_b8055_firmware, cpe:/o:xerox:altalink_b8065_firmware, cpe:/o:xerox:altalink_b8075_firmware, cpe:/o:xerox:altalink_b8090_firmware, cpe:/o:xerox:altalink_c8030_firmware, cpe:/o:xerox:altalink_c8035_firmware, cpe:/o:xerox:altalink_c8045_firmware, cpe:/o:xerox:altalink_c8055_firmware, cpe:/o:xerox:altalink_c8070_firmware

Required KB Items: Tenable.ot/Xerox

Patch Publication Date: 12/4/2020

Vulnerability Publication Date: 3/29/2021

Reference Information

CVE: CVE-2021-28670