CVE-2018-17944
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change.
Published:Mar 12, 2019
Last Modified:Nov 21, 2024
EPS:Mar 12, 2019
EPSS Score:0.00281
CVSS Score:4.9
Affected Products
Vendor
Product
Action
Vendor
Lexmark
Product
Cx725h
Lexmark
Cx725h
Vendor
Lexmark
Product
Cx725h Firmware
Lexmark
Cx725h Firmware
Vendor
Lexmark
Product
Cx820
Lexmark
Cx820
Vendor
Lexmark
Product
Cx820 Firmware
Lexmark
Cx820 Firmware
Vendor
Lexmark
Product
Cx825
Lexmark
Cx825
Vendor
Lexmark
Product
Cx825 Firmware
Lexmark
Cx825 Firmware
Vendor
Lexmark
Product
Cx860
Lexmark
Cx860
Vendor
Lexmark
Product
Cx860 Firmware
Lexmark
Cx860 Firmware
Vendor
Lexmark
Product
Xc4150
Lexmark
Xc4150
Vendor
Lexmark
Product
Xc4150 Firmware
Lexmark
Xc4150 Firmware
Vendor
Lexmark
Product
Xc6152
Lexmark
Xc6152
Vendor
Lexmark
Product
Xc6152 Firmware
Lexmark
Xc6152 Firmware
Vendor
Lexmark
Product
Xc8155
Lexmark
Xc8155
Vendor
Lexmark
Product
Xc8155 Firmware
Lexmark
Xc8155 Firmware
Vendor
Lexmark
Product
Xc8160
Lexmark
Xc8160
Vendor
Lexmark
Product
Xc8160 Firmware
Lexmark
Xc8160 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
