CVE-2023-26070

Severity
9.8CRITICAL
EPSS
0.3%
top 43.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10

Description

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages26 packages

NVDlexmark/lp_firmware< lp.jb.p837+1
NVDlexmark/lr_firmware< lr.sk.p838+6
NVDlexmark/lw80_firmware< lw80.sb7.p234+13
NVDlexmark/cslbl_firmware< cslbl.081.232
NVDlexmark/cslbn_firmware< cslbn.081.232

🔴Vulnerability Details

2
GHSA
GHSA-qrr8-87qr-7r3c: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4)2023-04-10
CVEList
CVE-2023-26070: Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4)2023-04-10
CVE-2023-26070 (CRITICAL CVSS 9.8) | Certain Lexmark devices through 202 | cvebase.io