Lexmark has another security issue
Dark Reading magazine, and many other IT publications reported on a new security vulnerability in Lexmark printers and MFPs
- Lexmark is a division of Ninestar of China
- “A nasty SSRF bug in Web Services plagues a laundry list of enterprise printers”
- Allows hackers to implement a remote code execution (RCE)
- apparently affects more than 120 different Lexmark printers and MFPs
- carries a score of 9 out of 10 on the CVSS vulnerability-severity scale
- a server-side request forgery (SSRF) vulnerability
- Lexmark has issued a firmware patch and noted that disabling Web Services on TCP port 65002 altogether will also provide protection.