MEDIUM · 4.6

CVE-2016-3145

Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows phy...

Vulnerability Description

Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.

CVSS Score

4.6

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LexmarkPrinter Firmware>= pp, <= pp.021.062
LexmarkCx820De-
LexmarkCx820Dtfe-
LexmarkCx825De-
LexmarkCx825Dte-
LexmarkCx825Dtfe-
LexmarkCx860De-
LexmarkCx860Dte-
LexmarkCx860Dtfe-
LexmarkXc6152De-
LexmarkXc6152Dtfe-
LexmarkXc8155De-
LexmarkXc8155Dte-
LexmarkXc8160De-
LexmarkXc8160Dte-
LexmarkC4150-
LexmarkCs720De-
LexmarkCs720Dte-
LexmarkCs725De-
LexmarkCs725Dte-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-3145?

CVE-2016-3145 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows phy...

How severe is CVE-2016-3145?

CVE-2016-3145 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-3145?

Check the references section above for vendor advisories and patch information. Affected products include: Lexmark Printer Firmware, Lexmark Cx820De, Lexmark Cx820Dtfe, Lexmark Cx825De, Lexmark Cx825Dte.