Cyber Posture

CVE-2020-35546

Critical

Published: 19 February 2025

Published
19 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0010 27.4th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

Security Summary

CVE-2020-35546 is an Incorrect Access Control vulnerability (CWE-284) affecting Lexmark MX6500 LW75.JD.P296 and previous devices. The flaw stems from improper implementation in the access control settings, enabling unauthorized actions despite configured restrictions.

The vulnerability carries a CVSS v3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating exploitation is possible remotely over the network by unauthenticated attackers with low complexity and no user interaction. Attackers can achieve high confidentiality and integrity impacts, such as accessing or modifying sensitive data and configurations, while availability remains unaffected.

Lexmark advisories address mitigation through their support portal at http://support.lexmark.com and a dedicated security alert PDF at https://publications.lexmark.com/publications/security-alerts/CVE-2020-35546.pdf, which security practitioners should review for patching guidance and workarounds.

Details

CWE(s)
CWE-284

References