CRITICAL · 9.8

CVE-2016-1896

Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypas...

Vulnerability Description

Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LexmarkPrinter Firmware<= cb.02.048
LexmarkC4150All versions
LexmarkCs720DeAll versions
LexmarkCs720DteAll versions
LexmarkCs725DeAll versions
LexmarkCs725DteAll versions
LexmarkCx725DeAll versions
LexmarkCx725DheAll versions
LexmarkCx725DtheAll versions
LexmarkXc4150All versions
LexmarkC6160All versions
LexmarkCs820DeAll versions
LexmarkCs820DteAll versions
LexmarkCs820DtfeAll versions
LexmarkCx820DeAll versions
LexmarkCx820DtfeAll versions
LexmarkCx825DeAll versions
LexmarkCx825DteAll versions
LexmarkCx825DtfeAll versions
LexmarkCx860DeAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1896?

CVE-2016-1896 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypas...

How severe is CVE-2016-1896?

CVE-2016-1896 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-1896?

Check the references section above for vendor advisories and patch information. Affected products include: Lexmark Printer Firmware, Lexmark C4150, Lexmark Cs720De, Lexmark Cs720Dte, Lexmark Cs725De.