Back

CRITICAL

Combination Path Traversal and Concurrent Execution vulnerability exists within the embedded web server

Published Feb 13, 2025

Description

The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.

Affected products

Remediation

Vendor solution

Lexmark recommends a firmware update if your device has affected firmware.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Lexmark
Published Feb 13, 2025
Updated Feb 13, 2025
Reserved Feb 7, 2025

CISA Vulnrichment

Updated Feb 13, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Lexmark
Published Feb 13, 2025
Updated Feb 13, 2025

GitHub

No data