CVE-2018-17944

UnknownEPSS 0.89%

Last modified

CVE-2018-17944 is a vulnerability of currently unknown severity. On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.

Description

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

Metrics

EPSS Probability
0.89%

54.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LexmarkCx725h FirmwareAll versions
LexmarkCx820 FirmwareAll versions
LexmarkCx825 FirmwareAll versions
LexmarkCx860 FirmwareAll versions
LexmarkXc4150 FirmwareAll versions
LexmarkXc6152 FirmwareAll versions
LexmarkXc8155 FirmwareAll versions
LexmarkXc8160 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17944?
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.
How severe is CVE-2018-17944?
Severity scoring for CVE-2018-17944 is pending analysis. The EPSS model estimates a 0.89% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17944?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17944?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST