CVE-2023-26068
published 2023-04-10CVE-2023-26068: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
11.63%
95.6th percentile
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lexmark | cslbl_firmware | < cslbl.081.232 | cslbl.081.232 |
| lexmark | cslbn_firmware | < cslbn.081.232 | cslbn.081.232 |
| lexmark | csnzj_firmware | < csnzj.081.232 | csnzj.081.232 |
| lexmark | cstat_firmware | < cstat.081.233 | cstat.081.233 |
| lexmark | cstmh_firmware | < cstmh.081.233 | cstmh.081.233 |
| lexmark | cstpc_firmware | < cstpc.081.232 | cstpc.081.232 |
| lexmark | cxlbl_firmware | < cxlbl.081.232 | cxlbl.081.232 |
| lexmark | cxlbn_firmware | < cxlbn.081.232 | cxlbn.081.232 |
| lexmark | cxnzj_firmware | < cxnzj.081.232 | cxnzj.081.232 |
| lexmark | cxtat_firmware | < cxtat.081.233 | cxtat.081.233 |
| lexmark | cxtmm_firmware | < cxtmm.081.232 | cxtmm.081.232 |
| lexmark | cxtpc_firmware | < cxtpc.081.232 | cxtpc.081.232 |
| lexmark | cxtpp_firmware | < cxtpp.081.233 | cxtpp.081.233 |
| lexmark | cxtpp_firmware | < cstpp.081.233 | cstpp.081.233 |
| lexmark | cxtzj_firmware | < cxtzj.081.232 | cxtzj.081.232 |
| lexmark | mslbd_firmware | < mslbd.081.232 | mslbd.081.232 |
| lexmark | mslsg_firmware | < mslsg.081.232 | mslsg.081.232 |
| lexmark | msngm_firmware | < msngm.081.232 | msngm.081.232 |
| lexmark | msngw_firmware | < msngw.081.232 | msngw.081.232 |
| lexmark | mstgw_firmware | < mstgw.081.232 | mstgw.081.232 |
| lexmark | mxlbd_firmware | < mxlbd.081.232 | mxlbd.081.232 |
| lexmark | mxlsg_firmware | < mxlsg.081.232 | mxlsg.081.232 |
| lexmark | mxngm_firmware | < mxngm.081.232 | mxngm.081.232 |
| lexmark | mxtct_firmware | < mxtct.081.232 | mxtct.081.232 |
| lexmark | mxtgm_firmware | < mxtgm.081.232 | mxtgm.081.232 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests to /cgi-bin/fax_change_faxtrace_settings without authentication headers/credentials, particularly POST requests manipulating parameters such as FT_Custom_lbtrace. ↗
- →Alert on shell metacharacters or command injection payloads in fax configuration parameters (e.g., FT_Custom_lbtrace) submitted to the Lexmark embedded web server. ↗
- ·The vulnerability is only exploitable when no Admin user has been configured on the device — i.e., the user selected 'Set up Later' during initial setup. Devices with an Admin user configured are NOT exposed. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/174763/Lexmark-Device-Embedded-Web-Server-Remote-Code-Execution.htmlhttps://publications.lexmark.com/publications/security-alerts/CVE-2023-26068.pdfhttps://support.lexmark.com/alerts/http://packetstormsecurity.com/files/174763/Lexmark-Device-Embedded-Web-Server-Remote-Code-Execution.htmlhttps://publications.lexmark.com/publications/security-alerts/CVE-2023-26068.pdfhttps://support.lexmark.com/alerts/
2023-04-10
Published