9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.
AI Analysis
A Path Traversal vulnerability in Xerox FreeFlow Core version 8.0.4 allows attackers to access unauthorized files and execute remote code, enabling arbitrary command execution on the server.
Basic Information
ID
CVE-2025-8356
Source
Xerox
Published
Aug 8, 2025 at 15:40
Modified
Aug 8, 2025 at 15:49
Affected Product
Vendor
Xerox
Product
FreeFlow Core
Affected Versions
Xerox FreeFlow Core 0
CWE Classification
AI Assessment
AI Severity
Critical
Vendor
Xerox
Product
FreeFlow Core
Version
8.0.4