PT-2022-6628 · Lexmark · Lexmark

Published

2022-12-28

·

Updated

2025-02-11

·

CVE-2023-26063

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lexmark devices through 2023-02-19
Description The issue is related to accessing a resource by using an incompatible type, which can lead to remote code execution. This is associated with the pagemaker microprogram software of Lexmark multifunctional devices, specifically when handling the NAME parameter. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For Lexmark devices through 2023-02-19, consider restricting access to the pagemaker service until a patch is available. As a temporary workaround, avoid using the NAME parameter in the affected service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2023-02890
CVE-2023-26063
ZDI-23-663

Affected Products

Lexmark