CVE-2023-26065

CRITICALCVSS 9.8/10EPSS 0.71%

Last modified

CVE-2023-26065 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain Lexmark devices through 2023-02-19 have an Integer Overflow.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.

Description

Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.71%

48.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LexmarkCxtpc Firmware< cxtpc.081.232
LexmarkCstpc Firmware< cstpc.081.232
LexmarkMxtct Firmware< mxtct.081.232
LexmarkMxtpm Firmware< mxtpm.081.232
LexmarkCxtmm Firmware< cxtmm.081.232
LexmarkMslsg Firmware< mslsg.081.232
LexmarkMxlsg Firmware< mxlsg.081.232
LexmarkMslbd Firmware< mslbd.081.232
LexmarkMxlbd Firmware< mxlbd.081.232
LexmarkMsngm Firmware< msngm.081.232
LexmarkMxngm Firmware< mxngm.081.232
LexmarkMxtgm Firmware< mxtgm.081.232
LexmarkMsngw Firmware< msngw.081.232
LexmarkMstgw Firmware< mstgw.081.232
LexmarkMxtgw Firmware< mxtgw.081.232
LexmarkCslbn Firmware< cslbn.081.232
LexmarkCslbl Firmware< cslbl.081.232
LexmarkCxlbn Firmware< cxlbn.081.232
LexmarkCxlbl Firmware< cxlbl.081.232
LexmarkCstzj Firmware< cstzj.081.232
LexmarkCsnzj Firmware< csnzj.081.232
LexmarkCxtzj Firmware< cxtzj.081.232
LexmarkLw80 Firmware< lw80.sb7.p234
LexmarkLw80 Firmware< lw80.dn2.p234
LexmarkLw80 Firmware< lw80.dn4.p234
LexmarkLw80 Firmware< lw80.dn7.p234
LexmarkLw80 Firmware< lw80.tu.p234
LexmarkLw80 Firmware< lw80.sa.p234
LexmarkLw80 Firmware< lw80.mg.p234
LexmarkLw80 Firmware< lw80.jd.p234
LexmarkLw80 Firmware< lw80.vyl.p234
LexmarkLw80 Firmware< lw80.vy2.p234
LexmarkLw80 Firmware< lw80.vy4.p234
LexmarkLw80 Firmware< lw80.gm2.p234
LexmarkLw80 Firmware< lw80.gm4.p234
LexmarkLw80 Firmware< lw80.gm7.p234
LexmarkLhs60 Firmware< lhs60.cm2.p760
LexmarkLhs60 Firmware< lhs60.cm4.p760
LexmarkLhs60 Firmware< lhs60.hc.p760
LexmarkLhs60 Firmware< lhs60.hv.p760
LexmarkLhs60 Firmware< lhs60.tp.p760
LexmarkLhs60 Firmware< lhs60.vk.p760
LexmarkLhs60 Firmware< lhs60.ny.p760
LexmarkLhs60 Firmware< lhs60.mr.p760
LexmarkLhs60 Firmware< lhs60.hk.p760
LexmarkLhs60 Firmware< lhs60.tq.p760
LexmarkLhs60 Firmware< lhs60.jr.p760
LexmarkLr Firmware< lr.sk.p838
LexmarkLr Firmware< lr.ske.p838
LexmarkLr Firmware< lr.lbh.p838

Showing 50 of 56 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-26065?
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
How severe is CVE-2023-26065?
CVE-2023-26065 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.71% probability of exploitation in the next 30 days.
How do I fix CVE-2023-26065?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-26065?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST