SSRF Vulnerability in Lexmark Printers and Multifunction Devices
CVE-2023-23560

9.8CRITICAL

Key Information:

Vendor

Lexmark

Vendor
CVE Published:
23 January 2023

What is CVE-2023-23560?

Certain Lexmark printers and multifunction devices are vulnerable to a Server-Side Request Forgery (SSRF) attack due to inadequate input validation. This flaw allows attackers to send unauthorized requests from the server to internal or external resources, potentially leading to information disclosure or unauthorized access. It is crucial for users of affected products to implement security measures promptly and stay updated with the latest security alerts.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.