CVE-2020-36201

moderate-risk
Published 2021-01-26

An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.

Do I need to act?

-
0.15% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Workcentre 3655 Firmware
Workcentre 3655I Firmware
Workcentre 5865 Firmware
Workcentre 5875 Firmware
Workcentre 5890 Firmware
Workcentre 5865I Firmware
Workcentre 5875I Firmware
Workcentre 5945 Firmware
Workcentre 5955 Firmware
Workcentre 5945I Firmware
Workcentre 5955I Firmware
Workcentre 6655 Firmware
Workcentre 6655I Firmware
Workcentre 7220 Firmware
Workcentre 7225 Firmware
Workcentre 7220I Firmware
Workcentre 7225I Firmware
Workcentre 7830I Firmware
Workcentre 7835I Firmware
Workcentre 7845I Firmware

Affected Vendors

49
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 1/34 · Minimal
Exposure 22/34 · High