9.8CVSS
9.5AI Score
0.003EPSS
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
7.5CVSS
7.5AI Score
0.004EPSS
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
5.4CVSS
5.2AI Score
0.001EPSS
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
5.4CVSS
5.3AI Score
0.001EPSS
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
5.4CVSS
5.2AI Score
0.001EPSS
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.
5.3CVSS
5.3AI Score
0.002EPSS
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
5.4CVSS
5.3AI Score
0.001EPSS
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 befo...
5.4CVSS
5.3AI Score
0.001EPSS
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
9.8CVSS
9.8AI Score
0.023EPSS
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
8.8CVSS
8.6AI Score
0.002EPSS
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
9.8CVSS
9.5AI Score
0.05EPSS
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80..P246, i.e., ' ' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to re...
7.5CVSS
7.3AI Score
0.001EPSS