02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: LexmarkAn input validation vulnerability in the SE Menu allows an attacker to execute arbitrary code.
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
- SSVC decision
- ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
- AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
- Technical ImpacttotalSuccessful exploitation gives total control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.- EPSS probability
- 0.98% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 59.6% of scored records. A rank, not a probability.
- NVD base score
- 9.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- NVD analysis status
- Deferred. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2024-02-28 02:38Z2 YR AGO
- Last updated
- 2024-08-23 14:56Z2 YR AGO
- Reserved
- 2023-12-11
- Assigning CNA
- Lexmark
- Record state
- PUBLISHED
- Severity
- Critical (CVSS 9.1)
- CNA CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Weaknesses
- CWE-20Improper Input ValidationClass
- Data version
- 5.1
- Document digest
- 28ce2d5cd0606e341ff22d37ca76942437c2ec14718535d69b6ccd39ad9dfd6e
05 Affected products
PAIRS: 68VendorProductVersionsPlatforms
lexmarkcxtpc_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstpc_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxtct_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxtpm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtmm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmslsg_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxlsg_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmslbd_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxlbd_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmsngm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmstgm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxngm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkms3150 to lw90.tl2.p205— lexmarkmxtgm_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmsngw_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmstgw_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmxtgw_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcslbn_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcslbl_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxlbn_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxlbl_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstzj_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcsnzj_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtzj_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxnzj_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtpp_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstpp_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstat_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtat_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstmh_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtmh_firmware0 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmsnsn_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmstsn_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcx4100 to lw90.gm4.p205— lexmarkmxtsn_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcsngv_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcstgv_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkcxtgv_firmware0 to 222.030, 230.001 to 230.041, 230.075 to 230.078, 230.200 to 230.203— lexmarkmx4100 to lw90.sb4.p205— lexmarkmx6100 to lw90.sb7.p205— lexmarkms7110 to lw90.dn2.p205— lexmarkmx7100 to lw90.tu.p205— lexmarkms9110 to lw90.sa.p205— lexmarkmx9100 to lw90.mg.p205— lexmarkcs5100 to lw90.vy4.p205— lexmarkcx5100 to lw90.gm7.p205— lexmarkms3100 to lw80.prl.p249— lexmarkmx3100 to lw80.sb2.p249— lexmarkcs3100 to lw80.vyl.p249— lexmarkcs4100 to lw80.vy2.p249— lexmarkcx3100 to lw80.gm2.p249— lexmarkc7460 to lhs60.cm2.p763— lexmarkc7480 to lhs60.cm4.p763— lexmarkc7920 to lhs60.hc.p763— 8 further entries not shown. The complete list is in the raw JSON document.
SRC: CNA
Lexmark recommends a firmware update if your device has affected firmware.