Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
7.5CVSS
7.5AI Score
0.004EPSS
9.1CVSS
9.2AI Score
0.002EPSS
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
5.3CVSS
5.3AI Score
0.001EPSS
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
5.4CVSS
5.2AI Score
0.001EPSS
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
5.4CVSS
5.3AI Score
0.001EPSS
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
5.4CVSS
5.2AI Score
0.001EPSS
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.
5.3CVSS
5.3AI Score
0.002EPSS
9.8CVSS
9.4AI Score
0.002EPSS
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
7.5CVSS
7.3AI Score
0.001EPSS
9.8CVSS
9.4AI Score
0.003EPSS
9.8CVSS
9.4AI Score
0.003EPSS
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
5.4CVSS
5.3AI Score
0.001EPSS
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 befo...
5.4CVSS
5.3AI Score
0.001EPSS
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
9.8CVSS
9.8AI Score
0.023EPSS
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
8.8CVSS
8.6AI Score
0.002EPSS
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
9.8CVSS
9.5AI Score
0.05EPSS