NA

CVE-2023-26067

Published: 10/04/2023 Updated: 19/09/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

This vulnerability allows network-adjacent malicious users to execute arbitrary code on affected installations of Lexmark MC3224i printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the fax_change_faxtrace_settings script. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the httpd user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lexmark cxtpc_firmware

lexmark cstpc_firmware

lexmark mxtct_firmware

lexmark mxtpm_firmware

lexmark cxtmm_firmware

lexmark mslsg_firmware

lexmark mxlsg_firmware

lexmark mslbd_firmware

lexmark mxlbd_firmware

lexmark msngm_firmware

lexmark mxngm_firmware

lexmark mxtgm_firmware

lexmark msngw_firmware

lexmark mstgw_firmware

lexmark mxtgw_firmware

lexmark cslbn_firmware

lexmark cslbl_firmware

lexmark cxlbn_firmware

lexmark cxlbl_firmware

lexmark csnzj_firmware

lexmark cxtzj_firmware

lexmark cxnzj_firmware

lexmark cxtpp_firmware

lexmark cstat_firmware

lexmark cxtat_firmware

lexmark cstmh_firmware

Vendor Advisories

Exploits

An unauthenticated remote code execution vulnerability exists in the embedded webserver in certain Lexmark devices through 2023-02-19 The vulnerability is only exposed if, when setting up the printer or device, the user selects "Set up Later" when asked if they would like to add an Admin user If no Admin user is created, the endpoint /cgi-bin/fax ...

Github Repositories

Lexmark CVE-2023-26067

CVE-2023-34362 POCs for credential dumping, reverse shells, and playing music by abusing a command injection, CVE-2023-26067, affecting Lexmark Printers Technical Analysis A technical root cause analysis of the vulnerability can be found on our blog: wwwhorizon3ai/lexmark-command-injection-vulnerability-zdi-can-19470-pwn2own-toronto-2022 Summary This POC abuses a com

CVE-2023-34362 POCs for credential dumping, reverse shells, and playing music by abusing a command injection, CVE-2023-26067, affecting Lexmark Printers Technical Analysis A technical root cause analysis of the vulnerability can be found on our blog: wwwhorizon3ai/lexmark-command-injection-vulnerability-zdi-can-19470-pwn2own-toronto-2022 Summary This POC abuses a com