Xerox Product Security

Similar documents
Xerox Product Security

Product Security. Data Protection: Image Overwrite, Encryption and Disk Removal

Xerox Product Security

Xerox Multifunction Device Scan to SMB Support Month 00, 0000

Xerox Security Bulletin XRX12-011

Address Postscript and DLM Vulnerabilities v1.1 03/07/12

Cyber Security Advisory

Xerox Product Compatibility

Xerox Product Compatibility macos High Sierra

Xerox Security Bulletin XRX V1.0

SSL/TLS Security Assessment of e-vo.ru

U85026A Detector 40 to 60 GHz

Programming Note. Agilent Technologies Quick Reference Guide For the 8757D/E Scalar Network Analyzer

Version: $Revision: 1142 $

Service withdrawal: Selected IBM ServicePac offerings

Findings for

SSL/TLS Server Test of

Xerox Security Bulletin XRX08-009

SSL/TLS Server Test of grupoconsultorefe.com

Xerox Corporation 2006 Awards and Ratings

Power Analyzer Firmware Update Utility Version Software Release Notes

Cisco CallManager 4.0-PBX Interoperability: Lucent/Avaya Definity G3 MV1.3 PBX using 6608-T1 PRI NI2 with MGCP

Safety. Introduction

Version 1.1 March 22, Secure Installation and Operation of Your WorkCentre 4250/4260

E R T M S COMMUNICATION PLAN

This document is a preview generated by EVS

Mobile Connect Pro. Activate Your Account. 200MB Data every month for 3 years included. Mobile Broadband

February 2017 Version: 1.0. Xerox App Gallery 4.0 Information Assurance Disclosure

Easy Installation Guide

Training Notes Unity Real Time 2

VisiBroker for Visual Studio 2013

EUROPEAN READY-MIXED CONCRETE INDUSTRY STATISTICS YEAR

* See invoice to confirm length of service after which the service is subject to a separate charge.

Portable Hard Drive USB 2.0 User Guide

InfoPrint 6500 line matrix printer family features new intelligent cartridge ribbon system

Secure Installation and Operation of Your WorkCentre TM 232/238/245/255/265/275 or WorkCentre TM Pro 232/238/245/255/265/275

Defeating All Man-in-the-Middle Attacks

Uploading protocols and Assay Control Sets to the QIAsymphony SP via the USB stick

Xerox Corporation 2005 Product Awards and Ratings

Getting Help Information

Business Fact Sheet. Xerox in. the. Office

Items exceeding one or more of the maximum weight and dimensions of a flat. For maximum dimensions please see the service user guide.

4620, Quick Start

International Packets

DROWN - Breaking TLS using SSLv2

Upgrading MYOB BankLink Notes (desktop)

Graphic Inspector 2 User Guide

Product Information Bulletin. Clearswift SECURE Gateway 4.7

Unlimited UK mobile calls and unlimited UK texts Bolt On: Unlimited landlines Poland Bundle (400 minutes to mobiles & landlines) 3.

Service Overview. Dell Services. Service Description: PowerEdge & PowerVault Maintenance

VisiBroker Release Notes

MOTOCADDY App Instruction Manual. Motocaddy App User Guide P1.v5 January 2017

User s Manual. PNG140 Bluetooth Car Kit

See What's Coming in Oracle Express CPQ for Salesforce.com

EVA1 grip redesign allows greater production flexibility

Version 1.6 April 16, Secure Installation and Operation of Your WorkCentre 5030/5050

WORKSHOP ON ALL WEEE FLOWS 14/02/17 Alberto Canni Ferrari ERP Italy Country General Manager

SpectraGuard Sensor SS-300-AT-C-50 Technical Specifications

Cisco 3745 Gateway - PBX Interoperability: Avaya Definity G3 PBX using Q.931 PRI Network Side Interfaces to an H.323 Gateway

Verifying Real-World Security Protocols from finding attacks to proving security theorems

AN POST SCHEDULE OF CHARGES

Yamaha Manufacturer s Warranty

MINUTES AND TEXTS CUSTOMER MOBILE BOLT-ON GUIDE JUNE 2018 BOLT-ON WILL KEEP YOU IN CONTROL OF YOUR COSTS. INTERNATIONAL NUMBERS FROM YOUR MOBILE, THIS

Sonae/PT: Implications for fixed-line markets. Giulio Federico ACE Meeting 2008 Budapest, November

Section 10: BT Mobile Section 10b: BT Business Mobile Portfolio

Global Economic Indicators: Global Leading Indicators

This document is a preview generated by EVS

Lenovo ThinkPlus ThinkPad Protection warranty upgrades

DAP Controller FCO

8x Independent DMX Controller

EXPOFACTS. Exposure Factors Sourcebook for Europe GENERAL

Preventing POODLE Attacks on ecopy ShareScan

CUSTOMER GUIDE Interoute One Bridge Outlook Plugin Meeting Invite Example Guide

AN12120 A71CH for electronic anticounterfeit protection

Microsoft Dynamics 365 for Finance and Operations. Table of contents

RTPA2A. TekConnect probe adapter for real-time spectrum analyzers. Tektronix high-performance probing solutions. Applications. Notice to EU customers

Microsoft Dynamics 365 for Finance and Operations, Enterprise edition. Table of contents

Read me. Quark Print Collection 1.1 ReadMe INTRODUCTION 2. System REQUIREMENTS 2. INSTALLING: Mac OS 2. INSTALLING: Windows 3 UPDATING 3 REGISTERING 4

Troubleshooting Ethernet Problems with Your Oscilloscope APPLICATION NOTE

Agilent IntuiLink for Infiniium Software for the Agilent Technologies Infiniium-Series Oscilloscopes. Getting Started With Agilent IntuiLink

New ThinkPad X200 Tablet laptop models feature Intel Core 2 Duo processors

Vertical Market Trends: Western Europe, (Executive Summary) Executive Summary

1-Port USB Print Server quick installation guide Model

Cisco 2651XM Gateway - PBX Interoperability: Avaya Definity G3 PBX using Analog FXO Interfaces to an H.323 Gateway

This document is a preview generated by EVS

Welcome to Verizon Business Internet Global Utilization Statistics

Printing History Edition 1 May

GUIDE TO ONLINE APPLICATION FOR SPACE Individual and Group Applications 15 May 2013

Read me. QuarkXPress Server Manager 7.2 ReadMe. Minimum system REQUIREMENTS 2. INSTALLING QuarkXPress Server Manager: MAC OS 2

TLS1.2 IS DEAD BE READY FOR TLS1.3

CVE / "POODLE"

Quick Start Guide TP1692EN Issue 3

This document is a preview generated by EVS

SCANNING MADE SIMPLE. SERIAL PROGRAMMING COMMANDS manual

CRE investment weakens in Q as investors struggle to find product in prime markets

ISO/TS TECHNICAL SPECIFICATION. Automatic vehicle and equipment identification Intermodal goods transport Numbering and data structures

Using Your NI Software for DOS or Windows 3 with Windows 95/98

Overcoming the Compliance Challenges of VAT Remittance. 12 April :55 to 16:30 (CEST)

AN2672 Application note

STEVAL-SPBT4ATV3. USB dongle for the Bluetooth class 1 SPBT2632C1A.AT2 module. Features. Description

Transcription:

Xerox Product Security OpenSSL Vulnerabilities Poodle, Freak and Logjam Version 1.4 June 30, 2016 Page 1

Disclaimer The information provided in this Xerox Product Response is provided "as is" without warranty of any kind. Xerox Corporation disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Xerox Corporation be held responsible for any damages whatsoever resulting from user's use or disregard of the information provided in this Xerox Product Response including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Xerox Corporation has been advised of the possibility of damages. Some states do not allow the exclusion or limitation of liability for consequential damages so the foregoing limitation may not apply. 2016 Xerox Corporation. All rights reserved. DocUSP, BookMark Centreware, ColorQube, ConnectKey, CopyCentre, Digital Bookmark, Document Centre, DocuColor, Docuprint, Docutech, FaxCentre, FreeFlow, igen, Nuvera, Phaser, WorkCentre and FreeFlow are trademarks of Xerox Corporation in the United States and/or other countries. Other company trademarks are also acknowledged. Summary Information Three vulnerabilities in the OpenSSL libraries for SSL/TLS have been reported. These may open possibilities for man in the middle or brute force attempts to intercept data transmission possible. These vulnerabilities are commonly associated with the names Poodle, Freak and Logjam. Following is current status of many Xerox products. Information is accurate for the latest device software available to customers. Xerox recommends customers update to the latest available release. Xerox publishes security Mini Bulletins when vulnerabilities are remediated in product updates. Detailed security information can be found at (http://www.xerox.com/information-security/enus.html ). If additional information is needed, please contact Xerox technical support or submit a question here http://www.xerox.com/perl-bin/formeng.pl?form=product_security_information_request_7285. Page 2

Poodle Poodle Common vulnerability CVE-2014-3566. The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear text data via a paddingoracle attack, aka the "POODLE" issue. Xerox has removed SSLv3 support or provided a means for customers to disable it. This mitigates the vulnerability. Status below is valid for the latest software version available to customers. Phaser 3020 No Phaser 3052/3260 No Phaser 3300 No Phaser 3320 No Phaser 3600 No Phaser 3610 No Phaser 3635 MFP No Phaser 4600/4620 No Phaser 4622 No Phaser 5550 No WorkCentre 3025BI No WorkCentre 3025NI No WorkCentre 3210/3220 No WorkCentre 3215/3225 No WorkCentre 3315 No WorkCentre 3325 No WorkCentre 3550 No WorkCentre 3615 No WorkCentre 3655 No WorkCentre 4250 No WorkCentre 4260 No WorkCentre 4265 No WorkCentre 5135/5150 No WorkCentre 5225/5230 Yes WorkCentre 5325/5330/5335 No WorkCentre 5632/5638/5645/5655/5665/5675/5687 No WorkCentre 5735/5740/5745/5755/5765/5775/5790 No WorkCentre 5845/5855/5865/5875/5890 No WorkCentre 5945/5955 No Page 3

Poodle Xerox D Series D95A/D110/D125 No Xerox D Series D136 No ColorQube 8570/8870 No ColorQube 8580/8880 No ColorQube 8700/8900 No ColorQube 9201/9202/9203 CBC No ColorQube 9201/9202/9203 SBC No ColorQube 9301/9302/9303 No Phaser 6000/6010 Yes Phaser 6020 Windows No Phaser 6020 Mac No Phaser 6022 Windows No Phaser 6022 Mac No Phaser 6128/6128MFP Yes Phaser 6280 No Phaser 6500 No Phaser 6600 No Phaser 6700 No Phaser 7100 Yes Phaser 7500 No Phaser 7800 No WorkCentre 6015 N/NI Yes WorkCentre 6025 Windows No WorkCentre 6025 Mac No WorkCentre 6027 Windows No WorkCentre 6027 Mac No WorkCentre 6400 No WorkCentre 6505 No WorkCentre 6605 No WorkCentre 6655 No WorkCentre 7120/7125 No WorkCentre 7220/7225 No Page 4

Poodle WorkCentre 7425/7428/7435 Yes WorkCentre 7525/7530/7535/7545/7556 No WorkCentre 7755/7765/7775 No WorkCentre 7830/7835 No WorkCentre 7845/7855 No WorkCentre 7970 No Xerox Color 550/560/570 No Xerox Color C60/C70 No Xerox Color C75 Yes Xerox Color J75 Yes Versant 80 No Versant 2100 No Page 5

Freak Freak Common vulnerability CVE-2015-0204. This allows SSL servers to downgrade RSA to export strength. Export strength ciphers can be broken with brute force methods. Status below is valid for the latest software version available to customers. Phaser 3020 No Phaser 3052/3260 No Phaser 3300 No Phaser 3320 No Phaser 3600 No Phaser 3610 No Phaser 3635 MFP No Phaser 4600/4620 No Phaser 4622 No Phaser 5550 No WorkCentre 3025BI No WorkCentre 3025NI No WorkCentre 3210/3220 No WorkCentre 3215/3225 No WorkCentre 3315 Yes WorkCentre 3325 No WorkCentre 3550 No WorkCentre 3615 No WorkCentre 3655 No WorkCentre 4250 No WorkCentre 4260 No WorkCentre 4265 No WorkCentre 5135/5150 No WorkCentre 5225/5230 Yes WorkCentre 5325/5330/5335 Yes WorkCentre 5632/5638/5645/5655/5665/5675/5687 No WorkCentre 5735/5740/5745/5755/5765/5775/5790 No WorkCentre 5845/5855/5865/5875/5890 No WorkCentre 5945/5955 No Page 6

Freak Xerox D Series D95A/D110/D125 Yes Xerox D Series D136 Yes ColorQube 8570/8870 No ColorQube 8580/8880 No ColorQube 8700/8900 No ColorQube 9201/9202/9203 CBC No ColorQube 9201/9202/9203 SBC No ColorQube 9301/9302/9303 No Phaser 6000/6010 Yes Phaser 6020 Windows Yes Phaser 6020 Mac Yes Phaser 6022 Windows No Phaser 6022 Mac No Phaser 6128/6128MFP Yes Phaser 6280 Yes Phaser 6500 Yes Phaser 6600 No Phaser 6700 No Phaser 7100 No Phaser 7500 No Phaser 7800 No WorkCentre 6015 N/NI Yes WorkCentre 6025 Windows Yes WorkCentre 6025 Mac Yes WorkCentre 6027 Windows Yes WorkCentre 6027 Mac Yes WorkCentre 6400 No WorkCentre 6505 Yes WorkCentre 6605 No WorkCentre 6655 No WorkCentre 7120/7125 Yes Page 7

Freak WorkCentre 7220/7225 No WorkCentre 7425/7428/7435 Yes WorkCentre 7525/7530/7535/7545/7556 No WorkCentre 7755/7765/7775 No WorkCentre 7830/7835 No WorkCentre 7845/7855 No WorkCentre 7970 No Xerox Color 550/560/570 Yes Xerox Color C60/C70 Yes Xerox Color C75 Yes Xerox Color J75 Yes Versant 80 Yes Versant 2100 Yes Page 8

Logjam Logjam Common vulnerability CVE-2015-4000. This does not properly prevent TLS downgrade of Diffie Hellman key to 512 bits. These keys can be broken with brute force methods. Note this information is limited to the strict definition of this CVE. Many security scan tools will flag this as an issue if DH keys are less than 2048 bits. Xerox is not planning to limit keys to 2048 in the near future. Status below is valid for the latest software version available to customers. Phaser 3020 No Phaser 3052/3260 No Phaser 3300 No Phaser 3320 No Phaser 3600 No Phaser 3610 No Phaser 3635 MFP No Phaser 4600/4620 No Phaser 4622 No Phaser 5550 No WorkCentre 3025BI No WorkCentre 3025NI No WorkCentre 3210/3220 No WorkCentre 3215/3225 No WorkCentre 3315 Yes WorkCentre 3325 No WorkCentre 3550 No WorkCentre 3615 No WorkCentre 3655 No WorkCentre 4250 No WorkCentre 4260 No WorkCentre 4265 No WorkCentre 5135/5150 No WorkCentre 5225/5230 No WorkCentre 5325/5330/5335 No WorkCentre 5632/5638/5645/5655/5665/5675/5687 No WorkCentre 5735/5740/5745/5755/5765/5775/5790 No WorkCentre 5845/5855/5865/5875/5890 No WorkCentre 5945/5955 No Page 9

Logjam Xerox D Series D95A/D110/D125 No Xerox D Series D136 No ColorQube 8570/8870 No ColorQube 8580/8880 No ColorQube 8700/8900 No ColorQube 9201/9202/9203 CBC No ColorQube 9201/9202/9203 SBC No ColorQube 9301/9302/9303 No Phaser 6000/6010 No Phaser 6020 Windows No Phaser 6020 Mac No Phaser 6022 Windows No Phaser 6022 Mac No Phaser 6128/6128MFP No Phaser 6280 No Phaser 6500 No Phaser 6600 No Phaser 6700 No Phaser 7100 No Phaser 7500 No Phaser 7800 No WorkCentre 6015 N/NI No WorkCentre 6025 Windows No WorkCentre 6025 Mac No WorkCentre 6027 Windows No WorkCentre 6027 Mac No WorkCentre 6400 No WorkCentre 6505 No WorkCentre 6605 No WorkCentre 6655 No WorkCentre 7120/7125 No Page 10

Logjam WorkCentre 7220/7225 No WorkCentre 7425/7428/7435 No WorkCentre 7525/7530/7535/7545/7556 No WorkCentre 7755/7765/7775 No WorkCentre 7830/7835 No WorkCentre 7845/7855 No WorkCentre 7970 No Xerox Color 550/560/570 No Xerox Color C60/C70 No Xerox Color C75 No Xerox Color J75 No Versant 80 No Versant 2100 No Additional Information For additional information or clarification on any of the product information given here, contact your local Xerox Customer Support Centre (see table below); or visit the Xerox Website. United States 800-835-6100 Luxembourg 480123 Austria +43 1 2079000 Netherlands +31 020-6563620 Belgium +32 (2) 713 14 52 (Français), +32 (2) 713 14 53 Norway +47 81 500 308 (Nederlands) Canada 1-800-835-6100 Portugal, 707 200 578 Denmark +45 70107288 Spain +34 902 160 236 Finland +358 09 693 79 666 Sweden + 46 0771 178 808 France 0825 012 013 Switzerland French: 043 299 9001 German: 043 299 9000 Italian: 043 299 9002 Germany +49 180 5004392 UK +44 0870 9005501 Greece +30 801 11 93769 Italy +39 199 11 20 88 Xerox welcomes feedback on all documentation - send feedback via e-mail to: Product.Security@xerox.com. Page 11