CVE-2022-34886
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.
Affected (3)
Products: Lenovo: Gm265dn Firmware, Gm266dns Firmware, G263dns Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Lenovo Gm265dn | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 02.06.00.04.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Gm266dns | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 02.06.00.04.00 |
| Running on/with | Platform Versions |
|---|---|
Lenovo G263dns | All versions |
Related CWEs
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.