Network access possible: Lexmark SMB printer with 8.6 security vulnerability

B2B Cyber ​​Security ShortNews

Share post

A Server-Side Request Forgery (SSRF) vulnerability exists in newer Lexmark SMB devices. In some cases, an attacker can use SSRF to move through corporate networks to exploit otherwise inaccessible internal systems or extract secrets. Updates are available.

In its Security Advisory, Lexmark informs users of Lexmark devices for the SME sector about a highly dangerous security vulnerability with a CVSS value of 8.6 out of 10. This makes network access possible for attackers via Server-Side Request Forgery (SSRF). The manufacturer recommends an immediate update of the firmware of the affected devices.

Over 150 Lexmark models with SSRF vulnerability

Server-side request forgery (SSRF) is a web security vulnerability that allows an attacker to trick the server-side application into making requests to an unintended location. In a typical SSRF attack, the attacker could force the server to connect only to internal services within the company's infrastructure. In other cases, the attacker can force the server to connect to any external system. This could result in sensitive data such as: B. Credentials can be intercepted.

To quickly check the firmware, Lexmark says users should do the following: “To determine the firmware version of a device, select Settings -> Reports -> Menu Settings Page. If the firmware version listed under “Device Information” matches a firmware version listed in the Lexmark list, the version should be updated immediately.”

Direct to PDF at Lexmark.com

 

Matching articles on the topic

Network access possible: Lexmark SMB printer with 8.6 security vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in newer Lexmark SMB devices. In some cases an attacker can ➡ Read more

Phishing: Dangerous invoices from law firms

The Threat Fusion Center (TFC), a division of BlueVoyant, has uncovered the "NaurLegal" phishing campaign with fake invoices from law firms ➡ Read more

New danger: AI DarkGemini fulfills hackers' wishes

In addition to Google's AI Gemini, DarkGemini has now appeared and fulfills the wishes of cyber gangsters and malware writers. There are still first editions ➡ Read more

Dell PowerEdge servers with a highly dangerous vulnerability

Dell warns users of PowerEdge servers: A highly dangerous vulnerability in the BIOS of PowerEdge servers could give a malicious user increased rights management ➡ Read more

Darknet: 34 million Roblox credentials on offer

Kaspersky cybersecurity experts have discovered 34 million stolen credentials for the online game platform Roblox on the dark web. Identity theft and hacks for ➡ Read more

Critical CVSS 10.0 backdoor in XZ for Linux

The BSI has issued a warning about a critical 10.0 vulnerability in the XZ tool within Linux. Those affected are: ➡ Read more

Google names 97 observed zero-day vulnerabilities

There are many zero-day vulnerabilities, but not all of them are widely exploited. Google and Mandiant have observed 97 zero-day vulnerabilities that severely ➡ Read more

BKA destroys darknet marketplace “Nemesis Market”

The Federal Criminal Police Office BKA has shut down the illegal darknet marketplace “Nemesis Market”. The platform with over 150.000 users enabled mass trading ➡ Read more