CVE-2023-23560
Published Jan 23, 2023In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
- evidence mentions
- 4
- Buzz score
- 27.6
Vendor/product archive
7 CVEs tagged to lexmark / b3442_firmware — 4 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.