CVE-2023-23560

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
23/01/2023
Last modified:
02/04/2025

Description

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lexmark:b2236_firmware:*:*:*:*:*:*:*:* mslsg.081.234 (excluding)
cpe:2.3:h:lexmark:b2236:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b2338_firmware:*:*:*:*:*:*:*:* msngm.081.234 (excluding)
cpe:2.3:h:lexmark:b2338:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b2442_firmware:*:*:*:*:*:*:*:* msngm.081.234 (excluding)
cpe:2.3:h:lexmark:b2442:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b2546_firmware:*:*:*:*:*:*:*:* msngm.081.234 (excluding)
cpe:2.3:h:lexmark:b2546:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b2650_firmware:*:*:*:*:*:*:*:* msngm.081.234 (excluding)
cpe:2.3:h:lexmark:b2650:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b2865_firmware:*:*:*:*:*:*:*:* msngw.081.234 (excluding)
cpe:2.3:h:lexmark:b2865:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b3340_firmware:*:*:*:*:*:*:*:* mslbd.081.234 (excluding)
cpe:2.3:h:lexmark:b3340:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:b3442_firmware:*:*:*:*:*:*:*:* mslbd.081.234 (excluding)