peter bassill · operator
$ cve CVE-2016-1896 JSON

CVE-2016-1896

9.8
CRITICAL · CVSS 3.0 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.26% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-254
On CISA KEVno
Public exploitnone known
Published2016-01-27
Last modified2026-06-17

Affected (28)

VendorProduct
lexmarkc4150
lexmarkc6160
lexmarkcs720de
lexmarkcs720dte
lexmarkcs725de
lexmarkcs725dte
lexmarkcs820de
lexmarkcs820dte
lexmarkcs820dtfe
lexmarkcx725de
lexmarkcx725dhe
lexmarkcx725dthe
lexmarkcx820de
lexmarkcx820dtfe
lexmarkcx825de
lexmarkcx825dte
lexmarkcx825dtfe
lexmarkcx860de
lexmarkcx860dte
lexmarkcx860dtfe
lexmarkprinter firmware
lexmarkxc4150
lexmarkxc6152de
lexmarkxc6152dtfe
lexmarkxc8155de
lexmarkxc8155dte
lexmarkxc8160de
lexmarkxc8160dte

References

→ the Explorer  ·  watch your stack  ·  NVD