MEDIUM · 4.9

CVE-2018-17944

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, an...

Vulnerability Description

On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.

CVSS Score

4.9

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LexmarkCx725H Firmware-
LexmarkCx725H-
LexmarkCx820 Firmware-
LexmarkCx820-
LexmarkCx825 Firmware-
LexmarkCx825-
LexmarkCx860 Firmware-
LexmarkCx860-
LexmarkXc4150 Firmware-
LexmarkXc4150-
LexmarkXc6152 Firmware-
LexmarkXc6152-
LexmarkXc8155 Firmware-
LexmarkXc8155-
LexmarkXc8160 Firmware-
LexmarkXc8160-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-17944?

CVE-2018-17944 is a vulnerability with a CVSS score of 4.9 (MEDIUM). On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, an...

How severe is CVE-2018-17944?

CVE-2018-17944 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-17944?

Check the references section above for vendor advisories and patch information. Affected products include: Lexmark Cx725H Firmware, Lexmark Cx725H, Lexmark Cx820 Firmware, Lexmark Cx820, Lexmark Cx825 Firmware.