5.4

CVE-2019-18791

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LexmarkCx31x Firmware Version <= lw73.vyl.p263
   LexmarkCx31x Version-
LexmarkCx41x Firmware Version <= lw73.vy2.p263
   LexmarkCx41x Version-
LexmarkCx310 Firmware Version <= lw73.gm2.p263
   LexmarkCx310 Version-
LexmarkMs310 Firmware Version <= lw73.prl.p263
   LexmarkMs310 Version-
LexmarkMs312 Firmware Version <= lw73.prl.p263
   LexmarkMs312 Version-
LexmarkMs317 Firmware Version <= lw73.prl.p263
   LexmarkMs317 Version-
LexmarkMs410 Firmware Version <= lw73.prl.p263
   LexmarkMs410 Version-
LexmarkM1140 Firmware Version <= lw73.prl.p263
   LexmarkM1140 Version-
LexmarkMs315 Firmware Version <= lw73.tl2.p263
   LexmarkMs315 Version-
LexmarkMs415 Firmware Version <= lw73.tl2.p263
   LexmarkMs415 Version-
LexmarkMs417 Firmware Version <= lw73.tl2.p263
   LexmarkMs417 Version-
LexmarkMs51x Firmware Version <= lw73.pr2.p263
   LexmarkMs51x Version-
LexmarkMs610dn Firmware Version <= lw73.pr2.p263
   LexmarkMs610dn Version-
LexmarkMs617 Firmware Version <= lw73.pr2.p263
   LexmarkMs617 Version-
LexmarkM1145 Firmware Version <= lw73.pr2.p263
   LexmarkM1145 Version-
LexmarkM3150dn Firmware Version <= lw73.pr2.p263
   LexmarkM3150dn Version-
LexmarkMs71x Firmware Version <= lw73.dn2.p263
   LexmarkMs71x Version-
LexmarkM5163dn Firmware Version <= lw73.dn2.p263
   LexmarkM5163dn Version-
LexmarkMs810 Firmware Version <= lw73.dn2.p263
   LexmarkMs810 Version-
LexmarkMs811 Firmware Version <= lw73.dn2.p263
   LexmarkMs811 Version-
LexmarkMs812 Firmware Version <= lw73.dn2.p263
   LexmarkMs812 Version-
LexmarkMs817 Firmware Version <= lw73.dn2.p263
   LexmarkMs817 Version-
LexmarkMs818 Firmware Version <= lw73.dn2.p263
   LexmarkMs818 Version-
LexmarkMs810de Firmware Version <= lw73.dn4.p263
   LexmarkMs810de Version-
LexmarkM5155 Firmware Version <= lw73.dn4.p263
   LexmarkM5155 Version-
LexmarkM5163 Firmware Version <= lw73.dn4.p263
   LexmarkM5163 Version-
LexmarkMs812de Firmware Version <= lw73.dn7.p263
   LexmarkMs812de Version-
LexmarkM5170 Firmware Version <= lw73.dn7.p263
   LexmarkM5170 Version-
LexmarkMs91x Firmware Version <= lw73.sa.p263
   LexmarkMs91x Version-
LexmarkMx31x Firmware Version <= lw73.sb2.p263
   LexmarkMx31x Version-
LexmarkXm1135 Firmware Version <= lw73.sb2.p263
   LexmarkXm1135 Version-
LexmarkMx410 Firmware Version <= lw73.sb4.p263
   LexmarkMx410 Version-
LexmarkMx510 Firmware Version <= lw73.sb4.p263
   LexmarkMx510 Version-
LexmarkMx511 Firmware Version <= lw73.sb4.p263
   LexmarkMx511 Version-
LexmarkMx610 Firmware Version <= lw73.sb7.p263
   LexmarkMx610 Version-
LexmarkMx611 Firmware Version <= lw73.sb7.p263
   LexmarkMx611 Version-
LexmarkXm3150 Firmware Version <= lw73.sb7.p263
   LexmarkXm3150 Version-
LexmarkMx71x Firmware Version <= lw73.tu.p263
   LexmarkMx71x Version-
LexmarkMx81x Firmware Version <= lw73.tu.p263
   LexmarkMx81x Version-
LexmarkXm51xx Firmware Version <= lw73.tu.p263
   LexmarkXm51xx Version-
LexmarkXm71xx Firmware Version <= lw73.tu.p263
   LexmarkXm71xx Version-
LexmarkMx91x Firmware Version <= lw73.mg.p263
   LexmarkMx91x Version-
LexmarkXm91x Firmware Version <= lw73.mg.p263
   LexmarkXm91x Version-
LexmarkMx6500e Firmware Version <= lw73.jd.p263
   LexmarkMx6500e Version-
LexmarkC746 Firmware Version <= lhs60.cm2.p731
   LexmarkC746 Version-
LexmarkC748 Firmware Version <= lhs60.cm4.p731
   LexmarkC748 Version-
LexmarkCs748 Firmware Version <= lhs60.cm4.p731
   LexmarkCs748 Version-
LexmarkC792 Firmware Version <= lhs60.hc.p731
   LexmarkC792 Version-
LexmarkCs796 Firmware Version <= lhs60.hc.p731
   LexmarkCs796 Version-
LexmarkC925 Firmware Version <= lhs60.hv.p731
   LexmarkC925 Version-
LexmarkC950 Firmware Version <= lhs60.tp.p731
   LexmarkC950 Version-
LexmarkX548 Firmware Version <= lhs60.vk.p731
   LexmarkX548 Version-
LexmarkXs548 Firmware Version <= lhs60.vk.p731
   LexmarkXs548 Version-
LexmarkX74x Firmware Version <= lhs60.ny.p731
   LexmarkX74x Version-
LexmarkXs748 Firmware Version <= lhs60.ny.p731
   LexmarkXs748 Version-
LexmarkX792 Firmware Version <= lhs60.mr.p731
   LexmarkX792 Version-
LexmarkXs79x Firmware Version <= lhs60.mr.p731
   LexmarkXs79x Version-
LexmarkX925 Firmware Version <= lhs60.hk.p731
   LexmarkX925 Version-
LexmarkXs925 Firmware Version <= lhs60.hk.p731
   LexmarkXs925 Version-
LexmarkX95x Firmware Version <= lhs60.tq.p731
   LexmarkX95x Version-
LexmarkXs95x Firmware Version <= lhs60.tq.p731
   LexmarkXs95x Version-
Lexmark6500e Firmware Version <= lhs60.jr.p731
   Lexmark6500e Version-
LexmarkC734 Firmware Version <= lr.sk.p822
   LexmarkC734 Version-
LexmarkC736 Firmware Version <= lr.ske.p822
   LexmarkC736 Version-
LexmarkE46x Firmware Version <= lr.lbh.p822
   LexmarkE46x Version-
LexmarkT65x Firmware Version <= lr.jp.p822
   LexmarkT65x Version-
LexmarkX46x Firmware Version <= lr.bs.p822
   LexmarkX46x Version-
LexmarkX65x Firmware Version <= lr.mn.p822
   LexmarkX65x Version-
LexmarkX73x Firmware Version <= lr.fl.p822
   LexmarkX73x Version-
LexmarkW850 Firmware Version <= lp.jb.p821
   LexmarkW850 Version-
LexmarkX86x Firmware Version <= lp.sp.p821
   LexmarkX86x Version-
LexmarkCx410 Firmware Version <= lw73.gm4.p263
   LexmarkCx410 Version-
LexmarkXc2130 Firmware Version <= lw73.gm4.p263
   LexmarkXc2130 Version-
LexmarkCx510 Firmware Version <= lw73.gm7.p263
   LexmarkCx510 Version-
LexmarkXc2132 Firmware Version <= lw73.gm7.p263
   LexmarkXc2132 Version-
LexmarkCx51x Firmware Version <= lw73.vy4.p263
   LexmarkCx51x Version-
LexmarkMs610de Firmware Version <= lw73.pr4.p263
   LexmarkMs610de Version-
LexmarkM3150 Firmware Version <= lw73.pr4.p263
   LexmarkM3150 Version-
LexmarkXm1140 Firmware Version <= lw73.sb4.p263
   LexmarkXm1140 Version-
LexmarkXm1145 Firmware Version <= lw73.sb4.p263
   LexmarkXm1145 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.501
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.