First published: Thu Feb 13 2025(Updated: )
: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759, from *.*.P001 through *.*.P836.
Credit: 7bc73191-a2b6-4c63-9918-753964601853
Affected Software | Affected Version | How to fix |
---|---|---|
Lexmark CX Series | >=001.001:0<081.231>=*.*.P001>=*.*.P001>=*.*.P001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11346 is a critical vulnerability that allows resource injection through type confusion in specific Lexmark printer models.
To fix CVE-2024-11346, you should update your Lexmark printer firmware to the latest version as recommended by Lexmark International.
CVE-2024-11346 affects Lexmark CX, XC, and CS series printers with firmware versions from 001.001:0 to 081.231 and various P versions.
Resource injection in CVE-2024-11346 refers to unauthorized access or manipulation of resources due to improper type handling in the printer's Postscript interpreter.
Yes, CVE-2024-11346 can potentially be exploited remotely if the affected Lexmark printers are accessible over a network.