Xerox Printers Loop with Unreachable Exit Condition (CVE-2022-23968)

high Tenable OT Security Plugin ID 505561

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing is restarted as soon as the boot process finishes.
However, this boot loop can be resolved by a field technician. The TIFF file must have an incomplete Image Directory. Affected firmware versions include xx.42.01 and xx.50.61. NOTE: the 2022-01-24 NeoSmart article included believed to affect all previous and later versions as of the date of this posting but a 2022-01-26 vendor statement reports the latest versions of firmware are not vulnerable to this issue.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://twitter.com/mqudsi/status/1485756915187695618

http://www.nessus.org/u?5b2aa9b3

http://www.nessus.org/u?af59724f

Plugin Details

Severity: High

ID: 505561

File Name: tenable_ot_xerox_CVE-2022-23968.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/27/2026

Updated: 7/27/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2022-23968

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:xerox:phaser_6510_firmware, cpe:/o:xerox:versalink_b400_firmware, cpe:/o:xerox:versalink_b405_firmware, cpe:/o:xerox:versalink_b600_firmware, cpe:/o:xerox:versalink_b605_firmware, cpe:/o:xerox:versalink_b610_firmware, cpe:/o:xerox:versalink_b615_firmware, cpe:/o:xerox:versalink_b7025_firmware, cpe:/o:xerox:versalink_b7030_firmware, cpe:/o:xerox:versalink_b7035_firmware, cpe:/o:xerox:versalink_c400_firmware, cpe:/o:xerox:versalink_c405_firmware, cpe:/o:xerox:versalink_c500_firmware, cpe:/o:xerox:versalink_c505_firmware, cpe:/o:xerox:versalink_c600_firmware, cpe:/o:xerox:versalink_c605_firmware, cpe:/o:xerox:versalink_c7000_firmware, cpe:/o:xerox:versalink_c7020_firmware, cpe:/o:xerox:versalink_c7025_firmware, cpe:/o:xerox:versalink_c7030_firmware, cpe:/o:xerox:versalink_c8000_firmware, cpe:/o:xerox:versalink_c9000_firmware, cpe:/o:xerox:workcentre_6515_firmware

Required KB Items: Tenable.ot/Xerox

Patch Publication Date: 1/28/2022

Vulnerability Publication Date: 1/26/2022

Reference Information

CVE: CVE-2022-23968

CWE: 835