VDB
CVE-2023-51765
CVE-2023-51765
PUBLISHED
CVSS 9.300000190734863 CRITICAL
FreeFlow-Druckserver ist eine Druckserveranwendung für Xerox-Produktionsdrucker, die Flexibilität, umfangreiche Workflow-Optionen und eine Farbverwaltung bietet.
EPSS 1.08% · 62.0th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.08%
62.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xerox | Xerox FreeFlow Print Server v9 | |
| Open Source | Open Source sendmail | |
| Open Source | Open Source Postfix <3.9 | |
| Ubuntu | Ubuntu Linux | |
| IBM | IBM AIX 7.3 | |
| Xerox | Xerox FreeFlow Print Server v7 | |
| IBM | IBM AIX 7.2 | |
| Fedora | Fedora Linux | |
| IBM | IBM VIOS 3.1 | |
| Open Source | Open Source Exim | |
| IBM | IBM VIOS 4.1 | |
| Dell | Dell NetWorker | |
| SUSE | SUSE Linux | |
| Red Hat | Red Hat Enterprise Linux | |
| Debian | Debian Linux | |
| EMC | EMC Avamar | |
| Amazon | Amazon Linux 2 |
Timeline
- CVE Published
- Dec 24, 2023 EPSS Score
- Dec 24, 2023 PoC Published
- Jan 4, 2024 PoC Published
- Jan 4, 2024 PoC Published
- Jan 5, 2024 PoC Published
- Jan 5, 2024 PoC Published
- Jan 18, 2024 PoC Published
- Jan 22, 2024 EPSS Score
- Mar 20, 2024 EPSS Score
- Apr 18, 2024 EPSS Score
- May 16, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1248.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1248 advisory
- https://security.business.xerox.com/wp-content/uploads/2024/05/Xerox-Security-Bulletin-XRX24-010-for-Xerox%C2%AE-FreeFlow%C2%AE-Print-Server-v7.pdf advisory
- https://alas.aws.amazon.com/AL2/ALAS-2024-2688.html advisory
- https://securitydocs.business.xerox.com/wp-content/uploads/2024/11/Xerox-Security-Bulletin-XRX24-017-for-Xerox%C2%AE-FreeFlow%C2%AE-Print-Server-v9.pdf advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-3206 advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00020.html advisory
- https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/ advisory
- https://www.mail-archive.com/postfix-users@postfix.org/msg100901.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255852 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255869 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-c839e7294f advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-e0841c83bb advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-April/018274.html advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00004.html advisory
- https://www.dell.com/support/kbdoc/de-de/000227573/dsa-2024-348-security-update-for-dell-avamar-dell-networker-virtual-edition-nve-and-dell-powerprotect-dp-series-appliance-dell-integrated-data-protection-appliance-idpa-security-update-for-multiple-vulnerabilities advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-3206.json advisory
- https://alas.aws.amazon.com/ALAS-2024-1914.html advisory
- https://alas.aws.amazon.com/AL2/ALAS-2024-2420.html advisory
- https://www.postfix.org/smtp-smuggling.html advisory
…and 19 more