7.5

CVE-2018-18894

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lexmark6500e Firmware Version < lhs60.jr.p683
   Lexmark6500e Version-
LexmarkC748 Firmware Version < lhs60.cm4.p683
   LexmarkC748 Version-
LexmarkC79x Firmware Version < lhs60.hc.p683
   LexmarkC79x Version-
LexmarkC925 Firmware Version < lhs60.hv.p683
   LexmarkC925 Version-
LexmarkC95x Firmware Version < lhs60.tp.p683
   LexmarkC95x Version-
LexmarkCs41x Firmware Version < lw71.vy2.p216
   LexmarkCs41x Version-
LexmarkCs51x Firmware Version < lw71.vy4.p216
   LexmarkCs51x Version-
LexmarkCs748 Firmware Version <= lhs60.cm4.p683
   LexmarkCs748 Version-
LexmarkCs796 Firmware Version < lhs60.hc.p683
   LexmarkCs796 Version-
LexmarkCx410 Firmware Version < lw71.gm4.p216
   LexmarkCx410 Version-
LexmarkCx510 Firmware Version < lw71.gm7.p216
   LexmarkCx510 Version-
LexmarkM3150 Firmware Version < lw71.pr4.p216
   LexmarkM3150 Version-
LexmarkM5155 Firmware Version < lw71.dn4.p216
   LexmarkM5155 Version-
LexmarkM5163 Firmware Version < lw71.dn4.p216
   LexmarkM5163 Version-
LexmarkM5170 Firmware Version < lw71.dn7.p216
   LexmarkM5170 Version-
LexmarkMs610de Firmware Version < lw71.pr4.p216
   LexmarkMs610de Version-
LexmarkMs610dte Firmware Version < lw71.pr4.p216
   LexmarkMs610dte Version-
LexmarkMs810de Firmware Version < lw71.dn4.p216
   LexmarkMs810de Version-
LexmarkMs812de Firmware Version < lw71.dn7.p216
   LexmarkMs812de Version-
LexmarkMs91x Firmware Version < lw71.sa.p216
   LexmarkMs91x Version-
LexmarkMx410 Firmware Version < lw71.sb4.p216
   LexmarkMx410 Version-
LexmarkMx510 Firmware Version < lw71.sb4.p216
   LexmarkMx510 Version-
LexmarkMx511 Firmware Version < lw71.sb4.p216
   LexmarkMx511 Version-
LexmarkMx610 Firmware Version < lw71.sb7.p216
   LexmarkMx610 Version-
LexmarkMx611 Firmware Version < lw71.sb7.p216
   LexmarkMx611 Version-
LexmarkMx6500e Firmware Version <= lw71.jd.p216
   LexmarkMx6500e Version-
LexmarkMx71x Firmware Version < lw71.tu.p216
   LexmarkMx71x Version-
LexmarkMx81x Firmware Version < lw71.tu.p216
   LexmarkMx81x Version-
LexmarkMx91x Firmware Version < lw71.mg.p216
   LexmarkMx91x Version-
LexmarkSm91x Firmware Version < lw71.mg.p216
   LexmarkSm91x Version-
LexmarkX46x Firmware Version < lr.bs.p810
   LexmarkX46x Version-
LexmarkX548 Firmware Version < lhs60.vk.p683
   LexmarkX548 Version-
LexmarkX65x Firmware Version < lr.mn.p810
   LexmarkX65x Version-
LexmarkX73x Firmware Version < lr.fl.p810
   LexmarkX73x Version-
LexmarkX74x Firmware Version < lhs60.ny.p683
   LexmarkX74x Version-
LexmarkX792 Firmware Version < lhs60.mr.p683
   LexmarkX792 Version-
LexmarkX86x Firmware Version < lr.sp.p810
   LexmarkX86x Version-
LexmarkX925 Firmware Version < lhs60.hk.p683
   LexmarkX925 Version-
LexmarkX95x Firmware Version < lhs60.tq.p683
   LexmarkX95x Version-
LexmarkXc2132 Firmware Version < lw71.gm7.p216
   LexmarkXc2132 Version-
LexmarkXm1145 Firmware Version < lw71.sb4.p216
   LexmarkXm1145 Version-
LexmarkXm3150 Firmware Version < lw71.sb7.p216
   LexmarkXm3150 Version-
LexmarkXm51xx Firmware Version < lw71.tu.p216
   LexmarkXm51xx Version-
LexmarkXm71xx Firmware Version < lw71.tu.p216
   LexmarkXm71xx Version-
LexmarkXs478 Firmware Version < lhs60.ny.p683
   LexmarkXs478 Version-
LexmarkXs548 Firmware Version < lhs60.vk.p683
   LexmarkXs548 Version-
LexmarkXs79x Firmware Version < lhs60.mr.p683
   LexmarkXs79x Version-
LexmarkXs925 Firmware Version < lhs60.hk.p683
   LexmarkXs925 Version-
LexmarkXs95x Firmware Version < lhs60.tq.p683
   LexmarkXs95x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.475
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.