CVE-2018-18894

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/03/2020
Last modified:
20/03/2020

Description

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lexmark:6500e_firmware:*:*:*:*:*:*:*:* lhs60.jr.p683 (excluding)
cpe:2.3:h:lexmark:6500e:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:c748_firmware:*:*:*:*:*:*:*:* lhs60.cm4.p683 (excluding)
cpe:2.3:h:lexmark:c748:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:c79x_firmware:*:*:*:*:*:*:*:* lhs60.hc.p683 (excluding)
cpe:2.3:h:lexmark:c79x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:c925_firmware:*:*:*:*:*:*:*:* lhs60.hv.p683 (excluding)
cpe:2.3:h:lexmark:c925:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:c95x_firmware:*:*:*:*:*:*:*:* lhs60.tp.p683 (excluding)
cpe:2.3:h:lexmark:c95x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cs41x_firmware:*:*:*:*:*:*:*:* lw71.vy2.p216 (excluding)
cpe:2.3:h:lexmark:cs41x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cs51x_firmware:*:*:*:*:*:*:*:* lw71.vy4.p216 (excluding)
cpe:2.3:h:lexmark:cs51x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cs748_firmware:*:*:*:*:*:*:*:* lhs60.cm4.p683 (including)