6.5

CVE-2022-3429

A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Gm265dn Firmware Version -
   Lenovo ≫ Gm265dn Version -
Lenovo ≫ Gm266dns Firmware Version < 02.06.00.04.00
   Lenovo ≫ Gm266dns Version -
Lenovo ≫ G263dns Firmware Version < 02.06.00.04.00
   Lenovo ≫ G263dns Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.384
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Lenovo 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://iknow.lenovo.com.cn/detail/205041.html
Patch
Vendor Advisory