CVE-2016-3145: Infoleak
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3145?
CVE-2016-3145 has a medium severity level due to its exploitation potential allowing unauthorized access to sensitive information.
How do I fix CVE-2016-3145?
To mitigate CVE-2016-3145, update the printer firmware to the latest version provided by Lexmark.
What types of Lexmark printers are affected by CVE-2016-3145?
Lexmark printers with specific firmware versions ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 are vulnerable.
What kind of information can be accessed due to CVE-2016-3145?
CVE-2016-3145 may allow attackers to obtain sensitive information stored in the printer's memory or hard disk.
Is physical access required to exploit CVE-2016-3145?
Yes, exploiting CVE-2016-3145 requires physical proximity to the affected Lexmark printers.