CVE-2024-55927

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.
Configurations

No configuration.

History

24 Feb 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 7.6

29 Jan 2025, 12:15

Type Values Removed Values Added
References
  • {'url': 'https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf', 'source': '10b61619-3869-496c-8a1e-f291b0e71e3f'}
  • () https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf -

27 Jan 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Implementación de generación de tokens defectuosa e implementación de clave codificada
Summary (en) Flawed token generation implementation & Hard-coded key implementation (en) A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading to unauthorized access to sensitive functions.

23 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 18:15

Updated : 2025-02-24 18:15


NVD link : CVE-2024-55927

Mitre link : CVE-2024-55927

CVE.ORG link : CVE-2024-55927


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials