Overview
Certain Lexmark devices are vulnerable to unverified password changes and stored cross-site scripting attacks.
Description
CWE-620: Unverified Password Change - CVE-2013-6032
Certain models of Lexmark laser printers and MarkNet devices are vulnerable to an attack which allows a remote unauthenticated attacker to change the administrative password of the printer's web administration interface. The interface does not perform sufficient validation of the vac.255.GENPASSWORD parameter in POST requests to the /cgi-bin/postpf/cgi-bin/dynamic/config/config.html page, allowing an unauthenticated remote attacker to reset the administrative password to an empty string.
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2013-6033
Certain models of Lexmark laser printers are vulnerable to stored cross-site scripting attacks. The printers' administrative web interface does not perform sufficient validation of user input to the "Location" and "Contact Name" fields in the "General Settings" configuration page.
A list of affected models and firmware versions can be found at Lexmark's advisory page.
The CVSS score reflects CVE-2013-6032.
Impact
An attacker may be able to run arbitrary script in the context of a victim's browser. The attacker may also be able to gain full administrative control of the printer.
Solution
Apply an Update
Lexmark advises users to update to the latest firmware version. A list of affected models and firmware versions, as well as accompanying fixes, can be found at Lexmark's advisory page.