Lexmark Printers Race Condition (CVE-2020-35546)

medium Tenable OT Security Plugin ID 503886

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A race condition exists while processing the state of the two security jumpers in an MX6500e. This can cause occasional misreads of the security jumper state during boot, causing the device to incorrectly believe the security jumper state has changed. The result is that security access controls may be unexpectedly reset.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?8c1f608a

Plugin Details

Severity: Medium

ID: 503886

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 11/7/2025

Updated: 11/7/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v3

Risk Factor: Medium

Base Score: 4.6

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/o:lexmark:mx6500e_firmware

Required KB Items: Tenable.ot/Lexmark

Patch Publication Date: 2/3/2021

Vulnerability Publication Date: 2/3/2021

Reference Information

CVE: CVE-2020-35546