{"id":26610,"date":"2022-09-19T10:17:13","date_gmt":"2022-09-19T08:17:13","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=26610"},"modified":"2022-09-19T10:18:00","modified_gmt":"2022-09-19T08:18:00","slug":"lexmark-firmware-update-schliet-schwachstelle-und-korrigiert-windows-druckerproblem","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/09\/19\/lexmark-firmware-update-schliet-schwachstelle-und-korrigiert-windows-druckerproblem\/","title":{"rendered":"Lexmark firmware update closes vulnerability and fixes Windows printer issue"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/09\/19\/lexmark-firmware-update-schliet-schwachstelle-und-korrigiert-windows-druckerproblem\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Good news for owners of Lexmark printers. The manufacturer has finally provided the firmware updates for various models. On the one hand, these are supposed to eliminate a vulnerability in more than a hundred Lexmark printer models, which Lexmark already warned about in June 2022 (the update had to be withdrawn again). Furthermore, the firmware update is supposed to fix the USB communication problem in Windows, which was caused by the July 2022 security update.<\/p>\n<p><!--more--><\/p>\n<h2>Vulnerability and printer issue<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg01.met.vgwort.de\/na\/aa7acf8045ab4b84ab5bc2aa2b715665\" width=\"1\" height=\"1\">Since July 2022, owners of various Lexmark printers have been suffering from the problem that these devices only print incomprehensible stuff. The cause is the July 2022 security update for Windows &#8211; I had reported about it in the blog post <a href=\"https:\/\/borncity.com\/win\/2022\/07\/20\/windows-printer-issues-after-july-2022-patchday-and-fixes\/\">Windows: Printer issues after July 2022 patchday and fixes<\/a>. Even if the problem is caused by a Microsoft update, the problem seems to be related to the firmware of the device. <\/p>\n<p>The second issue in Lexmark printers is a vulnerability that affects more than a hundred models. Attackers who have already gained access to the printers' firmware can then infiltrate them via a vulnerability. Lexmark had already written the Security Advisory <a href=\"https:\/\/publications.lexmark.com\/publications\/security-alerts\/CVE-2022-29850.pdf\" target=\"_blank\" rel=\"noopener\">CVE-2022-29850<\/a> (PDF) in June 2022, but then made another revision in August 2022. <\/p>\n<p>However, the firmware updates provided had to be withdrawn at short notice after problems. Lexmark had then advised a revised firmware update for mid Sept 2022, which should fix the CVE-2022-29850 vulnerability in the firmware, but also fix the Windows printing issue. I had reported on this in the blog post <a href=\"https:\/\/borncity.com\/win\/2022\/09\/07\/schwachstelle-in-lexmark-druckern-firmware-update-mit-korrektur-eines-windows-bugs-kommt-erst-mitte-sept-2022\/\">Lexmark: Firmware update to fix Windows bug and vulnerability CVE-2022-29850 in mid-Sept. 2022<\/a> in mid Sept 2022.<\/p>\n<h2>Revised firmware update released<\/h2>\n<p>German blog reader Frederik S. had already emailed me last Thursday, September 15, 2022, with the information that the revised firmware was available on the Lexmark support pages. <\/p>\n<blockquote>\n<p>as information for you there is since today on the Lexmark support site the download of version 081.215, according to the release notes the USB bug as well as the CVE-2022-29850 is fixed.<\/p>\n<\/blockquote>\n<p>Also <a href=\"https:\/\/www.borncity.com\/blog\/2022\/09\/07\/schwachstelle-in-lexmark-druckern-firmware-update-mit-korrektur-eines-windows-bugs-kommt-erst-mitte-sept-2022\/#comment-132303\" target=\"_blank\" rel=\"noopener\">this comment<\/a> from Michael N. left in the German blog informed me, that he found the new firmware updates on the Lexmark site (thanks to both readers for the hint):<\/p>\n<blockquote>\n<p>Lexmark has the new firmware version 081.215 available for our models on the Lexmark support page as of today. The release notes describe many bugs that should be fixed. There is also talk of an 081.212 release, but I have never seen it, perhaps it was not public.<\/p>\n<\/blockquote>\n<p>Lexmark meanwhile published <a href=\"https:\/\/infoserve.lexmark.com\/ids\/ifc\/ids_topic.aspx?root=kb20211110015901013&amp;gid=&amp;id=v54759890&amp;topic=v55542258&amp;productCode=Lexmark_XM9145&amp;loc=en_NZ\" target=\"_blank\" rel=\"noopener\">this support post<\/a> about the USB printer problem and writes: Update <em>the printer to xxxxx.081.215 or the latest RIP firmware version. This can be done via the printer's EWS feature (requires a network connection to the Internet) or by downloading the firmware from Lexmark support and copying that version to a USB stick, inserting that stick into the printer's USB port (if available), and then selecting that version<\/em>. Firmware update instructions are also available on <a href=\"https:\/\/www.lexmark.com\/en_us\/support\/firmware-update-instructions.html\" target=\"_blank\" rel=\"noopener\">this Lexmark support page<\/a> &#8211; downloads should be possible via <a href=\"https:\/\/support.lexmark.com\/en_us\/drivers-downloads.html\" target=\"_blank\" rel=\"noopener\">this Lexmark Driver download page<\/a> after entering the model (currently not all firmware revisions has been released). The firmware was probably released there on September 16, 2022. Below is an excerpt from the release notes.<\/p>\n<blockquote>\n<pre><code>RELEASE NOTES: xxxAT.081.215, xxxBD.081.215, xxxBL.081.215, <br>xxxBN.081.215, xxx.GM.081.215, xxx.GW.081.215, xxxMH.081.215, <br>xxxMM.081.215, xxxPC.081.215, xxxPM.081.215, xxxPP.081.215, <br>xxxSG.081.215, xxxZJ.081.215 <br>&nbsp;<br>READ THIS FIRST: Special notes and considerations <br>&nbsp;<br>\u2212&nbsp; ***IMPORTANT*** If using Scan Center with a non-default value (default = \"-1\") for the <br>UCF settings de_network_fwCompatibilityLevel*, users must review the following <br>Knowledge Base article before upgrading to this release (this is not common): <br>\u2212&nbsp; <a href=\"https:\/\/infoserve.lexmark.com\/ids\/ifc\/ids_topic.aspx?root=v55305163&amp;amp;gid=v50974468&amp;id=v55305244&amp;topic=v55471172&amp;productCode=Lexmark_MX822&amp;loc=en_US\" target=\"_blank\" rel=\"noopener\">Scanning from Scan Center causes 900.00 error<\/a><br>\u2212&nbsp; Although this URL is specifically for the MX822, this article is applicable to all <br>multi-function devices (MFP's) using Scan Center <br>\u2212&nbsp; Firmware upgrade warning: <br>\u2212&nbsp; Any device running FW5.1 or older (xxxxx.051.yyy or smaller numbers) must first <br>update to a FW7 based release such as xxxxx.076.308 before upgrading to <br>xxxxx.081.001 or newer releases <br>\u2212&nbsp; MS32x-MS62x\/MX32x-MX62x Series devices and their equivalents running <br>xxxGM.04y.zzz firmware must first update to a firmware release between <br>xxxGM.070.001 and xxxGM.075.289 as an initial intermediate release before <br>updating to xxxxx.081.001 or newer releases <br>\u2212&nbsp; CS72x\/CX72x Series devices and their equivalents running ATL.03x.yyy or <br>ATL.02x.yyy firmware must first update to CSTAT.041.090 or CXTAT.041.090 as <br>an initial intermediate release before updating to a FW7 based release, such as <br>xxxxx.076.308, and then finally updating to xxxxx.081.001 or newer releases <br>\u2212&nbsp; CS82x\/CX82x and CX86x Series devices and their equivalents running <br>xxxPP.075.yyy or older firmware AND with extra memory (RAM) installed must <br>first update to a FW7.6 based release such as xxxPP.076.308 before upgrading <br>to xxxPP.081.001 or newer releases <br>\u2212&nbsp; Contact Lexmark Technical Support to obtain intermediate releases if needed&nbsp; <br>\u2212&nbsp; Firmware downgrade warning: <br>\u2212&nbsp; Devices manufactured with xxxxx.080.001 or newer firmware cannot have <br>firmware downgraded below the manufactured level <br>\u2212&nbsp; For all other devices, it is strongly recommended that a firmware downgrade is <br>NOT performed <br>\u2212&nbsp; Downgrading firmware from newer major firmware ECs to older major firmware <br>ECs will result in the loss of Apps, Security Features, and Settings <br>\u2212&nbsp; Contact Lexmark Technical Support and see KB Article SO8017 for more <br>information on the impacts of downgrading <br>\u2212&nbsp; Ensure the firmware you download is the correct one for the product you have \n<p>CUSTOMER RELEASE NOTES: <br>FW8.1, xxxAT.081.215, xxxBD.081.215, xxxBL.081.215, xxxBN.081.215, <br>xxxGM.081.215, xxxGW.081.215, xxxMH.081.215, xxxMM.081.215, PC.081.215, <br>xxxPM.081.215, xxxPP.081.215, xxxSG.081.215, and xxxZJ.081.215 for the following <br>devices&nbsp; <br>&nbsp;<br>Changes in 081.215 (since 081.212): <br>Security Issues Addressed: <br>\u2212&nbsp; Upgraded open-source components to apply latest security patches&nbsp; <br>Field Issues Addressed and Other Improvements:&nbsp; <br>\u2212&nbsp; Improvements to firmware flashing reliability <br>\u2212&nbsp; Fix for an issue where using the \"Fit to Page\" setting on the printer results in a <br>corrupted output for some print jobs <br>\u2212&nbsp; Fix for an issue where the CS\/CX73x devices are not responding to adjustments <br>to the left margin on the multipurpose feeder or input option trays (CSTMM and <br>CXTMM firmware) <br>\u2212&nbsp; Fix for an \"unsupported USB hub\" error on some devices with Marknet N8372 <br>options installed <br>\u2212&nbsp; Fix for an issue where \"fold\" settings for Copy shortcuts were not applied <br>correctly when the shortcut was launched via Shortcut Center <br>\u2212&nbsp; Fix for an unexpected output received when printing via USB cable from a <br>computer running Windows10 patched with KB5015807 or newer <br>\u2212&nbsp; Fix for a 912.32A crash on CS\/CX33x devices and their equivalents (CSLBL and <br>CXLBL firmware) <br>\u2212&nbsp; Update default print resolution of mono devices to 1200IQ to improve interaction <br>with newer drivers and\/or driverless print options.&nbsp; NOTE: device print resolution <br>setting will not be changed by applying this firmware update, a restore factory <br>defaults or out of service erase would have to be performed after installing this <br>update for the new default to apply <br>\u2212&nbsp; Fixes for multiple fax issues <br>\u25aa&nbsp; Fix for an issue where devices with fax modems are stuck with \"Busy, <br>please wait\" on screen during some boot up operations <br>\u25aa&nbsp; Fix for a missing \"Fax Transport\" setting in some configurations <br>\u25aa&nbsp; Fix for an inability to receive some HTTPS faxes <br>\u2212&nbsp; Fixes for multiple sources of 900.00 errors <br>\u25aa&nbsp; Fix for a 900.00 Kernel crash when connected via USB cable to a <br>computer running Windows10 patched with KB5015807 or newer <br>\u25aa&nbsp; Fix for an intermittent 900.00 crash when performing a Card Copy job or a <br>quick copy job (start copying by pressing green button from home screen) <br>\u25aa&nbsp; Fix for a 900.00 crash that occurs with some JBIG faxes \u25aa&nbsp; Fix for a reoccurring 900.00 crash every time the device powers up <br>\u25aa&nbsp; Fix for a 900.00 crash that occurs after the printer has been idle\/asleep <br>for multiple hours on CS\/CX82x and CX86x devices and their equivalents <br>(CSTPP and CXTPP firmware) <br>\u25aa&nbsp; Fix for a 900.00 crash while printing using CS\/CX33x devices and their <br>equivalents (CSLBL and CXLBL firmware) <br>\u25aa&nbsp; Fix for a 900.00 crash that occurs when switching wireless access points <br>(changing SSID's) <br>\u25aa&nbsp; Fix for an intermittent 900.00 crash when using some HTTPS fax <br>functions <br>&nbsp;<br>Changes in 081.212 (since 081.205): <br>Security Issues Addressed: <br>\u2212&nbsp; Upgraded open-source components to apply latest security patches <br>Field Issues Addressed and Other Improvements:&nbsp; <br>\u2212&nbsp; Fix for an issue where the printer does not boot all the way to a usable state after <br>updating firmware (sometimes stuck at \"Busy, please wait\", sometimes earlier in <br>boot) <br>\u2212&nbsp; Fix for an issue where CS\/CX82x and CX86x devices fail to boot if they have <br>4GB of RAM or more installed (CSTPP and CXTPP firmware) <br>\u2212&nbsp; Fix for an issue where faxes are not sent successfully if \"cover page\" is enabled <br>or \"hold the job\" is enabled and certain security configurations are present <br>\u2212&nbsp; Fix for an issue where the Lexmark Cloud Services Native Agent running on the <br>device intermittently stops communicating with the Lexmark Cloud <br>\u2212&nbsp; Prevent Lexmark Cloud Services connection from disabling itself when network <br>connection is lost <br>\u2212&nbsp; Fix for an issue where devices intermittently fail during SMB communication to a <br>Windows Server with STATUS_ACCESS_DENIED or <br>STATUS_DUPLICATE_OBJECTID <br>\u2212&nbsp; Fix to improve output from some MS\/MX72x and MS\/MX82x printers which <br>intermittently printed too light or too dark (MSNGW, MSTGW, and MXTGW <br>firmware) <br>\u2212&nbsp; Fix for an \"incorrect printer time\" error message at device power on <br>\u2212&nbsp; Fix for an issue where the secure element is intermittently not detected at device <br>power on causing an \"Error communicating with the secure element\" message to <br>appear on the device <br>\u2212&nbsp; Allow scanner firmware update even if scanner is disabled on CX92x devices <br>\u2212&nbsp; Fix for an issue where the device stops scanning in the middle of a job initiated <br>by an eSF app and remains stuck <br>\u2212&nbsp; Fix for a 912.45A crash on the CS\/CX33x devices and their equivalents (CSLBL <br>and CXLBL firmware) <br>\u2212&nbsp; Fix for an issue where MB2236 devices with a 2.8\" touch screen boot into the <br>\"special boot options\" menu if the paper tray is empty (MXLSG firmware - 2.8\" <br>touch screen operator panel only) \u2212&nbsp; eSCL scanning support for different resolutions for each color mode <br>\u2212&nbsp; Fix for an issue where import of PKCS12 device certificates fails <br>\u2212&nbsp; Updated some strings and translations for enhanced user experience <br>\u2212&nbsp; Multiple fixes for PDF and PCL-XL emulator errors <br>\u2212&nbsp; Fix for an 842.02 crash when performing a scan job on CX42x-62x devices <br>(CXNZJ and CXTZJ firmware) <br>\u2212&nbsp; Return printer network address instead of local-host when querying printer-more-<br>info URI IPP attribute <br>\u2212&nbsp; Fixes for multiple sources of 900.00 errors <br>\u25aa&nbsp; Fix for an intermittent 900.00 crash only on network connected printers <br>\u25aa&nbsp; Fix for a 900.00 crash when tapping \"Connected to Network\" on the <br>device operator panel <br>\u25aa&nbsp; Fix for intermittent 900.00 crashes at device boot up on the CS\/CX72x <br>devices and their equivalents (CSTAT and CXTAT firmware) <br>\u25aa&nbsp; Fix for other intermittent 900.00 crashes <br>&nbsp;<br>Changes in 081.205 (since 081.016): <br>Security Issues Addressed: <br>\u2212&nbsp; Additional mitigations for CVE-2022-29850 Compromised device remains <br>vulnerable after firmware update <br>\u2212&nbsp; Upgraded open-source components to apply latest security patches&nbsp; <br>\u2212&nbsp; Security improvements based on internal testing <br>Field Issues Addressed and Other Improvements:&nbsp; <br>\u2212&nbsp; Add support for space characters in SNMP Community Name <br>\u2212&nbsp; Adjust Fax Volume settings to support new fax card for certain devices (MXLBD, <br>CXLBL, and CXLBN firmware)&nbsp; <br>\u2212&nbsp; Fix for an issue where \"Keyboard Type\" setting must be changed twice in order <br>to take effect <br>\u2212&nbsp; Increase time necessary to hold keyboard button before extra characters appear <br>in order to reduce inadvertent clicks <br>\u2212&nbsp; Added \"Test SMTP Connection\" button to SMTP setup menu to improve setup <br>usability <br>\u2212&nbsp; Resolve an issue where adding\/removing \"Held Jobs\" from Home Screen <br>Customization via printer web page intermittently doesn't refresh the op panel <br>and\/or web page correctly <br>\u2212&nbsp; Fix for an issue where LDAP authentication fails in some environments using <br>username and password, but succeeds with username only <br>\u2212&nbsp; Resolve an issue where, under certain conditions, the printer web page <br>intermittently shows the printer status as \"Busy\" even if the printer is not in busy <br>state <br>\u2212&nbsp; Improvement to ensure apps are able to automatically scroll a list to the currently <br>selected item during a change prompt if the list is longer than one screen \u2013 for example, a list of languages where the currently selected language may be <br>toward the middle or bottom of the list <br>\u2212&nbsp; Fix for an issue that causes firmware updates to intermittently fail on some <br>devices&nbsp; <br>\u2212&nbsp; Improve messaging for firmware version comparison when updating via the <br>printer web page <br>\u2212&nbsp; Fixes for multiple sources of 900.00 errors <br>&nbsp;<br>Changes in 081.016: <br>New Features: <br>\u2212&nbsp; Improved usability on 2.8-inch touchscreen devices&nbsp; <br>\u2212&nbsp; Improved Initial Setup Wizard usability experience&nbsp; <br>\u2212&nbsp; Added opt-out model for anonymous data collection&nbsp; <br>\u2212&nbsp; New TPM hardware support <br>\u2212&nbsp; TLS v1.3 Server Support <br>\u2212&nbsp; WPA v3.0 support <br>\u2212&nbsp; IPP Everywhere 1.1 <br>\u2212&nbsp; Universal Print \u2013 Phase 2&nbsp; <br>\u2212&nbsp; Node locked setting bundles&nbsp; <br>\u2212&nbsp; Open Source JDK&nbsp; <br>\u2212&nbsp; Custom Factory Defaults support&nbsp; <br>\u2212&nbsp; Improved staple logic (Held Jobs) <br>Security Issues Addressed: <br>\u2212&nbsp; CVE-2022-29850 Compromised device remains vulnerable after firmware update <br>\u2212&nbsp; Upgraded open source components to apply latest security patches <br>\u2212&nbsp; Security improvements based on internal testing <br>Field Issues Addressed and Other Improvements: <br>\u2212&nbsp; Improved enrollment to Lexmark Cloud Services <br>\u2212&nbsp; Fix for an issue where certain Cipher List changes are not saved successfully <br>\u2212&nbsp; Added validation checking to General Fax Settings, Fax Server, and Email Reply <br>Address fields <br>\u2212&nbsp; Multiple fixes for fax receive issues <br>\u2212&nbsp; Resolve a permissions issue with installed userflash <br>\u2212&nbsp; Fix for an issue where an HBP driver generated job does not print on certain <br>devices <br>\u2212&nbsp; Multiple fixes for PS, PDF, and PCL emulator errors<\/code><\/p><\/pre>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>[German]Good news for owners of Lexmark printers. The manufacturer has finally provided the firmware updates for various models. On the one hand, these are supposed to eliminate a vulnerability in more than a hundred Lexmark printer models, which Lexmark already &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/09\/19\/lexmark-firmware-update-schliet-schwachstelle-und-korrigiert-windows-druckerproblem\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[448,580,2],"tags":[415,466,69,195,194],"class_list":["post-26610","post","type-post","status-publish","format-standard","hentry","category-devices","category-security","category-windows","tag-printer","tag-problem","tag-security","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/26610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=26610"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/26610\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=26610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=26610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=26610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}