Vulnerable Systems:
* Base Lexmark Model Printers
* IPDS DLE Printers
* Forms DLE Printers
* Barcode DLE Printers
* Prescribe DLE Printers
* PrintCryption DLE PRinters
Immune Systems:
N/A
These vulnerabilities could lead to remote code execution on the printer without authentication. Device freezes when a specialy PLJ request is sent to the daemon with an invalid argument on PJL INQUIRE command.
Patch Availability:
To obtain firmware that resolves this issue or if you have special code, please contact Lexmark s Technical Support Center to find your local support center.
Workaround:
The problem can be mitigated by restricting the network devices that are permitted to communicate with the printer.
To do this:
-Limit access to the printer by utilizing either the Restricted Server List feature, or IPsec if the printer supports this feature. Hence, by restricting the number of devices that can communicate with the printer, you limit the number of devices that can be exploited by the vulnerability.
-Power cycling the printer will remove any injected code, and remove any resulting 900 service error.
-Enable automatic HDD wiping on the device to eliminate risk associated to residual job data.