Vulnerabilities
51 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-40239 | Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-26068 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). NVD description · AI analysis pending | 9.8 group max | 12% |
| — | ||
| CVE-2023-23560 +1 in the same advisory: …22960 | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. NVD description · AI analysis pending | 9.8 group max | 14% |
| — | ||
| CVE-2022-29850 | Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots. Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2022-24935 | Lexmark products through 2022-02-10 have Incorrect Access Control. Lexmark products through 2022-02-10 have Incorrect Access Control. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2021-44735 | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. NVD description · AI analysis pending | 9.8 group max | 7% |
| — | ||
| CVE-2021-44736 | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature. The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2021-35449 | The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are aff The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2021-35469 | The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-10093 +1 in the same advisory: …10094 | A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2018-18894 | Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2016-6918 +1 in the same advisory: …1487 | Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. ( NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2019-19773 +1 in the same advisory: …19772 | Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2019-18791 | Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2019-16758 | In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2 In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system. NVD description · AI analysis pending | 7.5 | 17% | PoC |
| — | |
| CVE-2019-9930 | Various Lexmark products have an Integer Overflow. Various Lexmark products have an Integer Overflow. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2018-15519 | Various Lexmark devices have a Buffer Overflow (issue 1 of 2). Various Lexmark devices have a Buffer Overflow (issue 1 of 2). NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2018-15520 | Various Lexmark devices have a Buffer Overflow (issue 2 of 2). Various Lexmark devices have a Buffer Overflow (issue 2 of 2). NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2018-17944 | On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because stored credentials are not automatically deleted upon that type of hostname change. NVD description · AI analysis pending | 4.9 | <1% |
| — | ||
| CVE-2019-6489 | Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts. Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2017-13771 | Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attack Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2) cgi-bin/direct/printer/prtappauth/apps/ImportExportServlet. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2017-2821 +1 in the same advisory: …2822 | An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code execution. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2017-2806 | An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400 NVD description · AI analysis pending | 3.3 | <1% | PoC |
| — | |
| CVE-2016-4336 | An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bounds write which under the right circumstance could potentially be leveraged by an attacker to gain arbitrary code execution. NVD description · AI analysis pending | 9.8 group max | 4% | PoC |
| — | |
| CVE-2016-3145 | Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and E Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory. NVD description · AI analysis pending | 4.6 | <1% |
| — |