CVE-2017-13771: Lexmark Scan To Network

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2) cgi-bin/direct/printer/prtappauth/apps/ImportExportServlet.

Affected products

  • Lexmark Scan To Network: up to and including 3.2.9

Published 2017-09-07. Last modified 2026-06-17.