Xerox Printers Improper Authentication (CVE-2023-46327)

medium Tenable OT Security Plugin ID 505559

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://jvn.jp/en/vu/JVNVU96482726/index.html

https://security.business.xerox.com/en-us/documents/bulletins/

http://www.nessus.org/u?5964be67

http://www.nessus.org/u?e6effb10

Plugin Details

Severity: Medium

ID: 505559

File Name: tenable_ot_xerox_CVE-2023-46327.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/27/2026

Updated: 7/27/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/o:xerox:versalink_b405_firmware, cpe:/o:xerox:versalink_b605_firmware, cpe:/o:xerox:versalink_b615_firmware, cpe:/o:xerox:versalink_b7125_firmware, cpe:/o:xerox:versalink_b7130_firmware, cpe:/o:xerox:versalink_b7135_firmware, cpe:/o:xerox:versalink_c405_firmware, cpe:/o:xerox:versalink_c505_firmware, cpe:/o:xerox:versalink_c605_firmware, cpe:/o:xerox:versalink_c7000_firmware, cpe:/o:xerox:versalink_c7020_firmware, cpe:/o:xerox:versalink_c7025_firmware, cpe:/o:xerox:versalink_c7030_firmware, cpe:/o:xerox:versalink_c7120_firmware, cpe:/o:xerox:versalink_c7125_firmware, cpe:/o:xerox:versalink_c7130_firmware, cpe:/o:xerox:workcentre_6515_firmware

Required KB Items: Tenable.ot/Xerox

Patch Publication Date: 10/31/2023

Vulnerability Publication Date: 11/1/2023

Reference Information

CVE: CVE-2023-46327

CWE: 287