CVE-2016-3145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
22/04/2016
Last modified:
12/04/2025

Description

Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lexmark:printer_firmware:*:*:*:*:*:*:*:* pp (including) pp.021.062 (including)
cpe:2.3:h:lexmark:cx820de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx820dtfe:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx825de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx825dte:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx825dtfe:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx860de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx860dte:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx860dtfe:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc6152de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc6152dtfe:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc8155de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc8155dte:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc8160de:-:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc8160dte:-:*:*:*:*:*:*:*