vendor:
Lexmark Services Monitor
by:
Kevin Randall
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Lexmark Services Monitor
Affected Version From: 2.27.4.0.39
Affected Version To: 2.27.4.0.39
Patch Exists: NO
Related CWE: CVE-2019-16758
CPE: a:lexmark:lexmark_services_monitor:2.27.4.0.39
Platforms Tested: Windows Server 2012
2019
Lexmark Services Monitor 2.27.4.0.39 – Directory Traversal
The Lexmark Services Monitor version 2.27.4.0.39 is vulnerable to a Directory Traversal and Local File Inclusion vulnerability. An attacker can exploit this vulnerability to access files outside of the intended directory.
Mitigation:
Upgrade/migrate all Lexmark Services Monitor with Lexmark Remote Access Monitor (LRAM).