Description
A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
Any version before Ver.D(1.05)
Any version before Ver.F
Any version before Ver.F
Any version before Ver.F
Any version before Ver.E(1.06)
Any version before Ver.D
Any version before Ver.D
Any version before Ver.D
Any version before Ver.E
Any version before Ver.E
Any version before Ver.E
Any version before Ver.E
Credits
Lenovo thanks CNVD for reporting this issue.
References
iknow.lenovo.com.cn/detail/431734