4.6

CVE-2016-3145

Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lexmark ≫ Printer Firmware Version >= pp <= pp.021.062
   Lexmark ≫ Cx820de Version -
   Lexmark ≫ Cx820dtfe Version -
   Lexmark ≫ Cx825de Version -
   Lexmark ≫ Cx825dte Version -
   Lexmark ≫ Cx825dtfe Version -
   Lexmark ≫ Cx860de Version -
   Lexmark ≫ Cx860dte Version -
   Lexmark ≫ Cx860dtfe Version -
   Lexmark ≫ Xc6152de Version -
   Lexmark ≫ Xc6152dtfe Version -
   Lexmark ≫ Xc8155de Version -
   Lexmark ≫ Xc8155dte Version -
   Lexmark ≫ Xc8160de Version -
   Lexmark ≫ Xc8160dte Version -
Lexmark ≫ Printer Firmware Version >= cb <= cb.021.062
   Lexmark ≫ C4150 Version -
   Lexmark ≫ Cs720de Version -
   Lexmark ≫ Cs720dte Version -
   Lexmark ≫ Cs725de Version -
   Lexmark ≫ Cs725dte Version -
Lexmark ≫ Printer Firmware Version >= yk <= yk.021.062
   Lexmark ≫ C6160 Version -
Lexmark ≫ Printer Firmware Version >= yk <= yk.021.057
   Lexmark ≫ Cs820de Version -
   Lexmark ≫ Cs820dte Version -
   Lexmark ≫ Cs820dtfe Version -
Lexmark ≫ Printer Firmware Version >= atl <= atl.021.062
   Lexmark ≫ Cx725de Version -
   Lexmark ≫ Cx725dhe Version -
   Lexmark ≫ Cx725dthe Version -
   Lexmark ≫ Xc4150 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.263
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 0.9 3.6
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://support.lexmark.com/index?page=content&id=TE760
Vendor Advisory