PT-2025-6504 · Lexmark · Lexmark International Xc
Published
2025-02-13
·
Updated
2025-04-09
·
CVE-2024-11346
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Lexmark International CX, XC, CS, et. Al. versions 001.001:0 through 081.231
Lexmark International CX, XC, CS, et. Al. versions ..P001 through ..P233
Lexmark International CX, XC, CS, et. Al. versions ..P001 through ..P759
Lexmark International CX, XC, CS, et. Al. versions ..P001 through ..P836
Description
The issue is related to a 'Type Confusion' vulnerability in the Postscript interpreter modules of Lexmark International CX, XC, CS, et. Al., allowing Resource Injection.
Recommendations
For versions 001.001:0 through 081.231, consider disabling the Postscript interpreter modules until a patch is available.
For versions ..P001 through ..P233, restrict access to the Postscript interpreter modules to minimize the risk of exploitation.
For versions ..P001 through ..P759, avoid using the Postscript interpreter modules in sensitive operations until the issue is resolved.
For versions ..P001 through ..P836, apply configuration changes to limit the impact of the 'Type Confusion' vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lexmark International Xc