CVE-2016-1896
9.8
CRITICAL · CVSS 3.0 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.26% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-254 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-01-27 |
| Last modified | 2026-06-17 |
Affected (28)
| Vendor | Product |
|---|---|
| lexmark | c4150 |
| lexmark | c6160 |
| lexmark | cs720de |
| lexmark | cs720dte |
| lexmark | cs725de |
| lexmark | cs725dte |
| lexmark | cs820de |
| lexmark | cs820dte |
| lexmark | cs820dtfe |
| lexmark | cx725de |
| lexmark | cx725dhe |
| lexmark | cx725dthe |
| lexmark | cx820de |
| lexmark | cx820dtfe |
| lexmark | cx825de |
| lexmark | cx825dte |
| lexmark | cx825dtfe |
| lexmark | cx860de |
| lexmark | cx860dte |
| lexmark | cx860dtfe |
| lexmark | printer firmware |
| lexmark | xc4150 |
| lexmark | xc6152de |
| lexmark | xc6152dtfe |
| lexmark | xc8155de |
| lexmark | xc8155dte |
| lexmark | xc8160de |
| lexmark | xc8160dte |
References
→ the Explorer · watch your stack · NVD