ZDI-24-405: Lexmark CX331adwe IPP Server Authorization HTTP Header Heap-Based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-50739.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-405?
The severity of ZDI-24-405 is rated at 8.8 on the CVSS scale, indicating a high level of risk.
How do I fix ZDI-24-405?
To fix ZDI-24-405, ensure that you apply the latest firmware updates from Lexmark for the CX331adwe printer.
Who is affected by ZDI-24-405?
ZDI-24-405 affects installations of the Lexmark CX331adwe printer that are exposed to network-adjacent attackers.
Does ZDI-24-405 require authentication to exploit?
No, ZDI-24-405 does not require authentication to exploit the vulnerability.
What type of vulnerability is ZDI-24-405?
ZDI-24-405 is a vulnerability that allows network-adjacent attackers to execute arbitrary code on the affected printers.