CVE-2021-44736

CRITICAL

Lexmark MC3224i Firmware - Unauthenticated Improper Authentication via Initial Admin Setup Wizard

Title source: llm
STIX 2.1

Description

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.lexmark.com/alerts/
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-22-331/

Scores

CVSS v3 9.8
EPSS 0.0243
EPSS Percentile 82.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
lexmark/mc3224i_firmware
Published Jan 20, 2022
Tracked Since Feb 18, 2026