CVE-2021-44734

CRITICAL

Lexmark B2236 Firmware < mslsg.076.294 - Remote Code Execution via Embedded Web Server

Title source: llm
STIX 2.1

Description

Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.lexmark.com/alerts/
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-22-332/

Scores

CVSS v3 9.8
EPSS 0.0643
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (50)
lexmark/6500e_firmware < lhs60.jr.p753
lexmark/b2236_firmware < mslsg.076.294
lexmark/b2338_firmware < msngm.076.294
lexmark/b2442_firmware < msngm.076.294
lexmark/b2546_firmware < msngm.076.294
lexmark/b2650_firmware < msngm.076.294
lexmark/b2865_firmware < msngw.076.294
lexmark/b3340_firmware < mslbd.076.294
lexmark/b3442_firmware < mslbd.076.294
lexmark/c2132_firmware < lw80.vy4.p210
... and 40 more
Published Jan 20, 2022
Tracked Since Feb 18, 2026