CVE-2024-11347

HIGH

Lexmark International CX, XC, CS - Integer Overflow in Postscript Interpreter

Title source: llm
STIX 2.1

Description

Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Forced Integer Overflow.The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0040
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (50)
Lexmark International/CX, XC, CS, et. al. < CSLBL.230.401
Lexmark International/CX, XC, CS, et. al. < CSLBN.230.401
Lexmark International/CX, XC, CS, et. al. < CSNGV.240.042
Lexmark International/CX, XC, CS, et. al. < CSNZJ.240.042
Lexmark International/CX, XC, CS, et. al. < CSTAT.230.401
Lexmark International/CX, XC, CS, et. al. < CSTGV.240.042
Lexmark International/CX, XC, CS, et. al. < CSTLS.240.076
Lexmark International/CX, XC, CS, et. al. < CSTMH.230.401
Lexmark International/CX, XC, CS, et. al. < CSTMM.240.042
Lexmark International/CX, XC, CS, et. al. < CSTPC.240.042
... and 40 more
Published Feb 13, 2025
Tracked Since Feb 18, 2026