-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2017.0187
                      Xerox Security Bulletin XRX17AN
                              3 November 2017

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Xerox WorkCentre
Operating System:     Network Appliance
Impact/Access:        Cross-site Scripting           -- Remote with User Interaction
                      Provide Misleading Information -- Remote with User Interaction
                      Access Confidential Data       -- Remote with User Interaction
Resolution:           Patch/Upgrade
Member content until: Saturday, December  2 2017

OVERVIEW

        Xerox has identified multiple vulnerabilities in its WorkCentre 
        Multifunction printer products. [1]


IMPACT

        Xerox has given the following details about these vulnerabilities:
        
        " The problems identified have been rated a criticality level of 
        IMPORTANT. This SPAR release uses OpenSSL 1.0.2h.
        
        Includes fixes for the following:
         Security HP Web Inspect scan failures (Cross-Frame Scripting & 
          Insecure Transmission)
         XSS Vulnerability in LDAP and Login pages
         HTML Injection on Software page
         HTML Injection on Device Description page
         Reflected Cross Site Scripting Vulnerability on various pages
         HTML Injection on various page" [1]


MITIGATION

        Xerox recommends patching its affected products to the latest 
        version in order to fix these vulnerabilities. [1]


REFERENCES

        [1] Xerox Security Bulletin XRX17AN
            https://security.business.xerox.com/wp-content/uploads/2017/11/cert_Security_Mini_Bulletin_XRX17AN_for_ConnectKey_v1.0.pdf

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWfupB4x+lLeg9Ub1AQgW/Q//SXdvXyH78DIZkt4wsMh85ww9glRJS96z
z6i//bUjQj6Q7BKonRwVwh/OzV5hxCtnytIDZLWjZgnkVVX78TXjNwsl0VWsBGD2
05QeCfmiJDPf0Y48oYyoRU204YsKv68xsiGr5F3M6axT5KEOFxryiJaudC1tJ9CS
E1p6moLE9v8BeT8OGSerFbMeUp8bwpKv35KmHny+FQvd9oHnXuXqoPejaydC5Of/
mRAwXJlroU86TJiJhVKktWq2FL5dmWx2pp/0Vl4LVG+OGYC16aJY/70JxB+WIL9F
uqNmoQnseL4WNrXYMSc45AeeGYEZIM98ZRsNxK+Znx9t2VXrxg/bSncNnhpVDLHv
UzXpGDioRzw5nlhOc/ShR+gs9E/hQddo4nDHz1sLfCKdKO6Nxc5B2D7Xxeoec/In
dCM7hdVH3/XfOWCxj7snCnGiEncYnu0DqrsEHwcm1oMO0s8AcYnurVtmNn5WOVTh
pcw+Lh8dSd/t93qifaXVRRwcDYGdO86omrl0B6TPl1cFK8sODDP7QVVwafkvQfCB
1RRGtEjKPXtaIICTgIReONMpA9BC0cvS8NdQxX/ttUwpOyz8ps+SGra/lERHVAtX
9aAN7x9doQIf7hpbxFwIfU3N+JbgGMXRLwQ02giK57qU8ATtDOvOdGpPJ0V68YAL
tAjoP+PuVs8=
=TCx4
-----END PGP SIGNATURE-----