CVE Vulnerabilities

CVE-2022-45897

Cleartext Storage of Sensitive Information

Published: Jan 31, 2023 | Modified: Mar 28, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Workcentre_3550_firmwareXerox25.003.03.000 (including)25.003.03.000 (including)

Potential Mitigations

References