CVE-2023-26067
HIGHCVSS 8.1/10EPSS 37.84%
Last modified
CVE-2023-26067 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).. EPSS estimates a 37.84% chance of exploitation in the next 30 days.
Description
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lexmark | Cxtpc Firmware | < cxtpc.081.232 |
| Lexmark | Cstpc Firmware | < cstpc.081.232 |
| Lexmark | Mxtct Firmware | < mxtct.081.232 |
| Lexmark | Mxtpm Firmware | < mxtpm.081.232 |
| Lexmark | Cxtmm Firmware | < cxtmm.081.232 |
| Lexmark | Mslsg Firmware | < mslsg.081.232 |
| Lexmark | Mxlsg Firmware | < mxlsg.081.232 |
| Lexmark | Mslbd Firmware | < mslbd.081.232 |
| Lexmark | Mxlbd Firmware | < mxlbd.081.232 |
| Lexmark | Msngm Firmware | < msngm.081.232 |
| Lexmark | Mxngm Firmware | < mxngm.081.232 |
| Lexmark | Mxtgm Firmware | < mxtgm.081.232 |
| Lexmark | Msngw Firmware | < msngw.081.232 |
| Lexmark | Mstgw Firmware | < mstgw.081.232 |
| Lexmark | Mxtgw Firmware | < mxtgw.081.232 |
| Lexmark | Cslbn Firmware | < cslbn.081.232 |
| Lexmark | Cslbl Firmware | < cslbl.081.232 |
| Lexmark | Cxlbn Firmware | < cxlbn.081.232 |
| Lexmark | Cxlbl Firmware | < cxlbl.081.232 |
| Lexmark | Csnzj Firmware | < csnzj.081.232 |
| Lexmark | Cxtzj Firmware | < cxtzj.081.232 |
| Lexmark | Cxnzj Firmware | < cxnzj.081.232 |
| Lexmark | Cxtpp Firmware | < cxtpp.081.233 |
| Lexmark | Cxtpp Firmware | < cstpp.081.233 |
| Lexmark | Cstat Firmware | < cstat.081.233 |
| Lexmark | Cxtat Firmware | < cxtat.081.233 |
| Lexmark | Cstmh Firmware | < cstmh.081.233 |
| Lexmark | Cstmh Firmware | < cstmx.081.233 |
References
- https://support.lexmark.com/alerts/Vendor Advisory
- https://support.lexmark.com/alerts/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26067?
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
How severe is CVE-2023-26067?
CVE-2023-26067 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 37.84% probability of exploitation in the next 30 days.
How do I fix CVE-2023-26067?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-26061An issue was discovered in Nokia NetAct before 22 FP2211. On…5.4
- CVE-2023-26062A mobile network solution internal fault is found in Nokia W…7.8
- CVE-2023-26063Certain Lexmark devices through 2023-02-19 access a Resource…9.8
- CVE-2023-26064Certain Lexmark devices through 2023-02-19 have an Out-of-bo…9.8
- CVE-2023-26065Certain Lexmark devices through 2023-02-19 have an Integer O…9.8
- CVE-2023-26066Certain Lexmark devices through 2023-02-19 have Improper Val…9.8
- CVE-2023-26068Certain Lexmark devices through 2023-02-19 mishandle Input V…9.8
- CVE-2023-26069Certain Lexmark devices through 2023-02-19 mishandle Input V…9.8
- CVE-2023-2607The Multiple Page Generator Plugin for WordPress is vulnerab…7.2
- CVE-2023-26070Certain Lexmark devices through 2023-02-19 mishandle Input V…9.8
- CVE-2023-26071An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.…7.5
- CVE-2023-26072An issue was discovered in Samsung Mobile Chipset and Baseba…9.8
Are you affected by CVE-2023-26067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
