CVE detail
CVE-2023-23560
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- 30th January – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 30th January, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHE The ALPHV/BlackCat Ransomware group has allegedly hacked Westmont Hospitality Group, one of the largest privately-held hospitality businesses in the world. They claim to have obtained access to 262GB of the company’s data. Check […]
vendorresearch.checkpoint.comJan 30, 2023, 3:37 PM - Security Affairs newsletter Round 404 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Copycat Criminals mimicking Lockbit gang in northern Europe Sandworm APT targets Ukraine with new SwiftSlicer wiper […]
newssecurityaffairs.comJan 29, 2023, 3:16 PM Lexmark warns of a remote code execution (RCE) vulnerability impacting over 120 printer models, for which PoC code has been published.
newswww.securityweek.comJan 27, 2023, 2:51 PM- CVE-2023-23560 flaw exposes 100 Lexmark printer models to hackSecurity Affairs
Lexmark released a security firmware update to fix a remote code execution flaw, tracked as CVE-2023-23560, that impacts more than 100 printer models. Lexmark has released a security firmware update to address a remote code execution vulnerability, tracked as CVE-2023-23560, that impacts more than 100 printer models. The CVE-2023-23560 flaw is a server-side request forgery […]
newssecurityaffairs.comJan 27, 2023, 8:26 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-22960CVSS 7.5 · High
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
- CVE-2022-29850CVSS 8.1 · High
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
- CVE-2021-44737CVSS 8.8 · High
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
- CVE-2021-44735CVSS 9.8 · Critical
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
- CVE-2021-44734CVSS 9.8 · Critical
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
- CVE-2021-44738CVSS 9.8 · Critical
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.