CRITICAL
Combination Path Traversal and Concurrent Execution vulnerability exists within the embedded web server
Published Feb 13, 2025
9.1
CRITICALCVSS 3.1
EPSS 0.54%
Description
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.
Affected products
-
Affected
- ≥ 0, ≤ CSLBL.240.407
- ≥ 0, ≤ CSLBN.240.407
- ≥ 0, ≤ CSNGV.240.205
- ≥ 0, ≤ CSNZJ.240.205
- ≥ 0, ≤ CSTAT.240.407
- ≥ 0, ≤ CSTGV.240.205
- ≥ 0, ≤ CSTLS.240.205
- ≥ 0, ≤ CSTMH.240.407
- ≥ 0, ≤ CSTMM.240.205
- ≥ 0, ≤ CSTPC.240.205
- ≥ 0, ≤ CSTPP.240.407
- ≥ 0, ≤ CSTZJ.240.205
- ≥ 0, ≤ CXLBL.240.407
- ≥ 0, ≤ CXLBN.240.407
- ≥ 0, ≤ CXNZJ.240.205
- ≥ 0, ≤ CXTAT.240.407
- ≥ 0, ≤ CXTGV.240.205
- ≥ 0, ≤ CXTLS.240.205
- ≥ 0, ≤ CXTMH.240.407
- ≥ 0, ≤ CXTMM.240.205
- ≥ 0, ≤ CXTPC.240.205
- ≥ 0, ≤ CXTPP.240.407
- ≥ 0, ≤ CXTZJ.240.205
- ≥ 0, ≤ MSLBD.240.407
- ≥ 0, ≤ MSLSG.240.407
- ≥ 0, ≤ MSNGM.240.205
- ≥ 0, ≤ MSNGW.240.205
- ≥ 0, ≤ MSNSN.240.205
- ≥ 0, ≤ MSTGM.240.205
- ≥ 0, ≤ MSTGW.240.205
- ≥ 0, ≤ MSTSN.240.205
- ≥ 0, ≤ MXLBD.240.407
- ≥ 0, ≤ MXLSG.240.407
- ≥ 0, ≤ MXNGM.240.205
- ≥ 0, ≤ MXTCT.240.205
- ≥ 0, ≤ MXTGM.240.205
- ≥ 0, ≤ MXTGW.240.205
- ≥ 0, ≤ MXTLS.240.205
- ≥ 0, ≤ MXTPM.240.205
- ≥ 0, ≤ MXTSN.240.205
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Lexmark | CX, XC, CS, MS, MX, XM, et. al. | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Lexmark recommends a firmware update if your device has affected firmware.
Weaknesses (2)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Lexmark
Published Feb 13, 2025
Updated Feb 13, 2025
Reserved Feb 7, 2025
Link CVE-2025-1127
CISA Vulnrichment
Updated Feb 13, 2025
Red Hat
No data
GitHub
No data