CVE-2020-35546 Details
Description
Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.
A vulnerability exists in Lexmark MX6500 devices with firmware LW75.JD.P296 and earlier, allowing for incorrect access control management. This issue arises from a race condition that misreads the state of security jumpers during the boot process, leading to a reset of access controls to default values. The vulnerability can be exploited when the device is powered on or rebooted, causing the access control settings to revert, potentially allowing unauthorized access or actions.
Users can upgrade to Lexmark MX6500 firmware version LW75.JD.P297 or later to address this vulnerability. For assistance, contact Lexmark's Technical Support Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 19, 2025CISA-ADP
Assessed Feb 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://publications.lexmark.com/publications/security-alerts/CVE-2020-35546.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Lexmark MX6500e | <= LW75.JD.P296 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2025 | CVE Modified | CISA-ADP |
| Feb 19, 2025 | New CVE Received | [email protected] |
Volerion