CVE-2017-13771
CRITICALLexmark Scan TO Network < 3.2.9 - Insufficiently Protected Credentials
Title source: ruleDescription
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2) cgi-bin/direct/printer/prtappauth/apps/ImportExportServlet.
References (3)
Scores
CVSS v3
9.8
EPSS
0.0153
EPSS Percentile
81.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
Status
draft
Affected Products (1)
lexmark/scan_to_network
< 3.2.9
Timeline
Published
Sep 07, 2017
Tracked Since
Feb 18, 2026