Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.148683
Category:General
Title:Lexmark Printer Improper Input Validation Vulnerability (Jun 2022)
Summary:Multiple Lexmark printer devices are prone to an improper input; validation vulnerability.
Description:Summary:
Multiple Lexmark printer devices are prone to an improper input
validation vulnerability.

Vulnerability Insight:
Lexmark firmware is stored in a compressed read-only filesystem
that is continuously integrity checked as programs are loaded into RAM for execution. This means
that if a device is somehow compromised, a reboot should clear the issue from the device.

This vulnerability allows an attacker that has already compromised the device, and therefore has
the ability to modify internal configuration files, to make their compromise persistent, meaning
after a device is rebooted, it will remain compromised.

NOTE: This vulnerability cannot be used to compromise a device, it can only be used on a device
that has already been compromised by another means.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-29850
https://publications.lexmark.com/publications/security-alerts/CVE-2022-29850.pdf
https://support.lexmark.com/alerts/
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.