CVE-2023-50738
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Exploitability: 0.9 / Impact: 3.4
Source: 7bc73191-a2b6-4c63-9918-753964601853 (Secondary)
Description
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to
override this downgrade protection has been identified.
Related CWEs
CWE-1328
Security Version Number Mutable to Older Versions
Security-version number in hardware is mutable, resulting in the ability to downgrade (roll-back) the boot firmware to vulnerable code versions.
CWE-354
Improper Validation of Integrity Check Value
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
References (1)
Source: 7bc73191-a2b6-4c63-9918-753964601853
Timeline
No history available yet.