iTnews Asia
  • Home
  • News
  • Security

Lexmark printers need firmware patch

Lexmark printers need firmware patch

More than 150 models affected by RCEs.

By Richard Chirgwin on Mar 1, 2024 10:37AM

More than 150 models of Lexmark printers need a firmware update, following the disclosure of four critical remote code execution (RCE) vulnerabilities.

The bugs were reported through Trend Micro’s Zero Day Initiative (ZDI), with credited individuals including Sina Kheirkhah of Summoning Team; Chris Anastasio; Team PHPHooligans members Rick de Jager, Carlo Meijer and Jonathan Jagt; and Team Viettel.

CVE-2023-50737 [pdf] is a bug in the SE menu, which Lexmark said “contains information used by Lexmark to diagnose device errors”.

One of the menu routines can be exploited to run arbitrary code, the advisory stated, and the vulnerability carries a critical CVSS score of 9.1.

Lexmark said the SE menu should be restricted to trusted users only.

The vulnerable printers also have three vulnerabilities in their PostScript interpreters: CVE-2023-50736 [pdf], CVE-2023-50735 [pdf], and CVE-2023-50734 [pdf], all of which carry a critical CVSS score of 9.0.

The PostScript vulnerabilities have no workarounds; firmware updates are needed.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
lexmark security

Related Articles

  • Why is fragmentation the next big cybersecurity risk?
  • The maritime sector is now in the crosshairs of cybercriminals
  • Tips on how to harness AI to transform your DDoS protection into proactive cyber defence
  • Malaysia secures communications for the upcoming ASEAN Summit
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The maritime sector is now in the crosshairs of cybercriminals

The maritime sector is now in the crosshairs of cybercriminals

Why is fragmentation the next big cybersecurity risk?

Why is fragmentation the next big cybersecurity risk?

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Indonesia's national data centre suffers ransomware attack

Indonesia's national data centre suffers ransomware attack

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.