CVE-2021-44736: (Pwn2Own) Lexmark MC3224i Unprotected API Remote Code Execution Vulnerability
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
Other sources
This vulnerability allows remote attackers to remove authentication on affected installations of Lexmark MC3224i printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within URL handling. The issue results from the lack of proper restriction to a URL. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44736?
CVE-2021-44736 is a vulnerability that allows remote attackers to remove authentication on affected installations of Lexmark MC3224i printers.
How severe is CVE-2021-44736?
CVE-2021-44736 has a severity score of 9.8, which is considered critical.
What is the affected software for CVE-2021-44736?
The affected software includes Lexmark MC3224i printers with firmware versions and Lexmark Mc3224i Firmware.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers through the lack of proper restriction to a URL handling.
Are there any references for more information about CVE-2021-44736?
Yes, you can find more information about CVE-2021-44736 at the following references: [1] [2] [3]