CVE-2022-29850

HIGHCVSS 8.1/10EPSS 0.84%

Last modified

CVE-2022-29850 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.

Description

Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.84%

53.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LexmarkB2236 Firmware< mslsg.081.014
LexmarkMb2236 Firmware< mxlsg.081.014
LexmarkMs331 Firmware< mslbd.081.014
LexmarkMs431 Firmware< mslbd.081.014
LexmarkM1342 Firmware< mslbd.081.014
LexmarkB3442 Firmware< mslbd.081.014
LexmarkB3340 Firmware< mslbd.081.014
LexmarkXm1342 Firmware< mslbd.081.014
LexmarkMx331 Firmware< mxlbd.081.014
LexmarkMx431 Firmware< mxlbd.081.014
LexmarkMb3442 Firmware< mxlbd.081.014
LexmarkMs321 Firmware< msngm.081.014
LexmarkMs421 Firmware< msngm.081.014
LexmarkMs521 Firmware< msngm.081.014
LexmarkMs621 Firmware< msngm.081.014
LexmarkM1242 Firmware< msngm.081.014
LexmarkM1246 Firmware< msngm.081.014
LexmarkB2338 Firmware< msngm.081.014
LexmarkB2442 Firmware< msngm.081.014
LexmarkB2546 Firmware< msngm.081.014
LexmarkB2650 Firmware< msngm.081.014
LexmarkMs622 Firmware< mstgm.081.014
LexmarkM3250 Firmware< mstgm.081.014
LexmarkMx321 Firmware< mxngm.081.014
LexmarkMx421 Firmware< mxtgm.081.014
LexmarkMx521 Firmware< mxtgm.081.014
LexmarkMx522 Firmware< mxtgm.081.014
LexmarkMx622 Firmware< mxtgm.081.014
LexmarkXm1242 Firmware< mxtgm.081.014
LexmarkXm1246 Firmware< mxtgm.081.014
LexmarkXm3250 Firmware< mxtgm.081.014
LexmarkMb2442 Firmware< mxtgm.081.014
LexmarkMb2546 Firmware< mxtgm.081.014
LexmarkMb2650 Firmware< mxtgm.081.014
LexmarkMs725 Firmware< msngw.081.014
LexmarkMs821 Firmware< msngw.081.014
LexmarkMs823 Firmware< msngw.081.014
LexmarkMs825 Firmware< msngw.081.014
LexmarkB2865 Firmware< msngw.081.014
LexmarkMs822 Firmware< mstgw.081.014
LexmarkMs826 Firmware< mstgw.081.014
LexmarkM5255 Firmware< mstgw.081.014
LexmarkM5270 Firmware< mstgw.081.014
LexmarkMx721 Firmware< mxtgw.081.014
LexmarkMx722 Firmware< mxtgw.081.014
LexmarkMx822 Firmware< mxtgw.081.014
LexmarkMx826 Firmware< mxtgw.081.014
LexmarkXm5365 Firmware< mxtgw.081.014
LexmarkXm7355 Firmware< mxtgw.081.014
LexmarkXm7370 Firmware< mxtgw.081.014

Showing 50 of 118 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-29850?
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
How severe is CVE-2022-29850?
CVE-2022-29850 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.84% probability of exploitation in the next 30 days.
How do I fix CVE-2022-29850?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-29850?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST