CVE-2023-26066

Severity
9.8CRITICAL
EPSS
0.4%
top 38.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10

Description

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages26 packages

NVDlexmark/lp_firmware< lp.jb.p837+1
NVDlexmark/lr_firmware< lr.sk.p838+6
NVDlexmark/lw80_firmware< lw80.sb7.p234+13
NVDlexmark/cslbl_firmware< cslbl.081.232
NVDlexmark/cslbn_firmware< cslbn.081.232

🔴Vulnerability Details

2
CVEList
CVE-2023-26066: Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index2023-04-10
GHSA
GHSA-6783-6wx3-fm82: Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index2023-04-10
CVE-2023-26066 (CRITICAL CVSS 9.8) | Certain Lexmark devices through 202 | cvebase.io