Xerox has released a critical security bulletin addressing multiple vulnerabilities in its Xerox Workplace Suite, a widely used print management server solution.
These vulnerabilities, identified as CVE-2024-55925 through CVE-2024-55931, could allow attackers to bypass API security, manipulate headers, and exploit weak configurations, posing significant risks to organizations relying on the software for secure print and document management.
Are you from SOC/DFIR Teams? - Analyse Malware Files & Links with ANY.RUN Sandox -> Try for Free
The vulnerabilities affect Xerox Workplace Suite versions prior to 5.6.701.9. The issues range from API security bypasses to improper handling of sensitive data and flawed token implementations. Below is a breakdown of the critical vulnerabilities:
These vulnerabilities collectively undermine the security framework of Xerox Workplace Suite by exposing critical components such as API endpoints and session tokens to exploitation.
Cyril Servières of Orange Cyberdefense identified the vulnerabilities with support from Sébastien Desbordes of Airbus SE.
Xerox has addressed most of these vulnerabilities in version 5.6.701.9 of the Workplace Suite. Organizations are strongly advised to upgrade immediately to this version to mitigate risks. Additionally:
For CVE-2024-55931, which remains unresolved, organizations should adopt interim measures such as restricting access to session storage and using secure cookies wherever possible.
Xerox Workplace Suite users must act swiftly to apply the necessary patches and strengthen their overall security posture against potential exploitation.
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
A new wave of cyber threats is emerging as criminals increasingly weaponize AdaptixC2, a free…
Chinese-affiliated threat actor UNC6384 has been actively leveraging a critical Windows shortcut vulnerability to target…
Threat actors operating under the control of North Korea's regime have demonstrated continued technical sophistication…
Sophisticated threat actors have orchestrated a coordinated multilingual phishing campaign targeting financial and government organizations…
AzureHound, an open-source data collection tool designed for legitimate penetration testing and security research, has…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a…