Home

Description

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

PUBLISHED Reserved 2024-06-25 | Published 2024-10-17 | Updated 2025-09-17 | Assigner Xerox




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Product status

Default status
unaffected

103.xxx.024.18600 (custom)
affected

Default status
unaffected

103.xxx.024.18600
affected

Default status
unaffected

103.023.031.35105
affected

Default status
unaffected

103.xxx.013.14115
affected

Default status
unaffected

119.xxx.023.13006
affected

Default status
unaffected

111.xxx.003.11600
affected

Default status
unaffected

119.xxx.003.11705
affected

Default status
unaffected

075.060.004.07810
affected

Default status
unaffected

075.091.004.07810
affected

Default status
unaffected

075.110.004.07810
affected

Default status
unaffected

075.030.004.07810
affected

Default status
unaffected

075.010 004.07810
affected

Default status
unaffected

075.040.004.07810
affected

Default status
unaffected

075.080.004.07810
affected

Default status
unaffected

075.200.004.07810
affected

Default status
unaffected

075.050.004.07810
affected

Default status
unaffected

075.020.004.07810
affected

References

seclists.org/fulldisclosure/2024/Oct/17

securitydocs.business.xerox.com/...re-–-CVE-2024-6333-.pdf

cve.org (CVE-2024-6333)

nvd.nist.gov (CVE-2024-6333)

Download JSON