CWE
20
Advisory Published
Updated

CVE-2013-6032: Input Validation

First published: Tue Feb 04 2014(Updated: )

cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344, X64xef through LC2.TI.P325, C935dn through LC.JO.P091, C920 through LS.TA.P152, C78x through LC.IO.P187, X78x through LC2.IO.P335, C77x through LC.CM.P052, X772 through LC2.TR.P291, C53x through LS.SW.P069, C52x through LS.FA.P150, 25xxN through LCL.CU.P114, N4000 through LC.MD.P119, N4050e through GO.GO.N206, N70xxe through LC.CO.N309, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allows remote attackers to remove the Password Protect administrative password via the vac.255.GENPASSWORD parameter.

Credit: cret@cert.org

Affected SoftwareAffected VersionHow to fix
Lexmark 25xxn<=lcl.cu.p114
Lexmark C52x<=ls.fa.p150
Lexmark C53x<=ls.sw.p069
Lexmark C77x<=lc.cm.p052
Lexmark C78x<=lc.io.p187
Lexmark C920<=ls.ta.p152
Lexmark C935dn<=lc.jo.p091
Lexmark E250<=le.pm.p126
Lexmark E350<=le.ph.p129
Lexmark E450<=lm.sz.p124
Lexmark N4000<=lc.md.p119
Lexmark N4050e<=go.go.n206
Lexmark N70xxe<=lc.co.n309
Lexmark T64x<=ls.st.p343
Lexmark W840<=ls.ha.p252
Lexmark X642<=lc2.mb.p318
Lexmark X644<=lc4.be.p487
Lexmark X646<=lc2.mc.p373
Lexmark X64xef<=lc2.ti.p325
Lexmark X772<=lc2.tr.p291
Lexmark X78x<=lc2.io.p335
Lexmark X85x<=lc4.be.p487
Lexmark X94x<=lc.br.p141

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203