A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
Fixes

Solution

Upgrade to the version (or newer) indicated in the Product Impact section below. Applicable product updates for all affected products can be downloaded from the following link: here https://www.lenovoimage.com/index.php/services/servers_drivers


Workaround

No workaround given by the vendor.

References
History

Thu, 11 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-09-11T18:59:36.498Z

Reserved: 2025-08-19T19:47:09.027Z

Link: CVE-2025-9214

cve-icon Vulnrichment

Updated: 2025-09-11T18:59:32.884Z

cve-icon NVD

Status : Received

Published: 2025-09-11T19:15:35.723

Modified: 2025-09-11T19:15:35.723

Link: CVE-2025-9214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.