CVE Vulnerabilities

CVE-2022-45897

Cleartext Storage of Sensitive Information

Published: Jan 31, 2023 | Modified: Mar 28, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Workcentre_3550_firmware Xerox 25.003.03.000 (including) 25.003.03.000 (including)

Potential Mitigations

References