CVE-2018-5409

CRITICAL

PrinterLogic Print Management <18.3.1.96 - Code Injection

Title source: llm
STIX 2.1

Description

The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://kb.cert.org/vuls/id/169249/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108285

Scores

CVSS v3 9.8
EPSS 0.0108
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494 CWE-346
Status published
Products (1)
printerlogic/print_management < 18.3.1.96
Published May 08, 2019
Tracked Since Feb 18, 2026