Description
A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
Published: 2025-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to the version (or newer) indicated in the Product Impact section below. Applicable product updates for all affected products can be downloaded from the following link: here https://www.lenovoimage.com/index.php/services/servers_drivers

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28987 A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
References
History

Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Lenovo
Lenovo printer
Vendors & Products Lenovo
Lenovo printer

Thu, 11 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
Description A missing authentication vulnerability was reported in some Lenovo printers that could allow a user to view limited device information or modify network settings via the CUPS service.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2025-09-11T18:59:36.498Z

Reserved: 2025-08-19T19:47:09.027Z

Link: CVE-2025-9214

cve-icon Vulnrichment

Updated: 2025-09-11T18:59:32.884Z

cve-icon NVD

Status : Deferred

Published: 2025-09-11T19:15:35.723

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-9214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-12T09:11:13Z

Weaknesses