Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-26067

Severity
8.1HIGH
EPSS
93.0%
top 0.22%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 10

Description

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages26 packages

NVDlexmark/cslbl_firmware< cslbl.081.232
NVDlexmark/cslbn_firmware< cslbn.081.232
NVDlexmark/csnzj_firmware< csnzj.081.232
NVDlexmark/cstat_firmware< cstat.081.233
NVDlexmark/cstmh_firmware< cstmh.081.233+1

🔴Vulnerability Details

3
CVEList
CVE-2023-26067: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4)2023-04-10
GHSA
GHSA-v2qx-4m4h-cjmg: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4)2023-04-10
VulnCheck
lexmark cxtpc_firmware Improper Input Validation2023

💥Exploits & PoCs

1
Nuclei
Lexmark Printers - Command Injection
CVE-2023-26067 (HIGH CVSS 8.1) | Certain Lexmark devices through 202 | cvebase.io