CVE-2019-18791

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/02/2020
Last modified:
20/02/2020

Description

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lexmark:cx31x_firmware:*:*:*:*:*:*:*:* lw73.vyl.p263 (including)
cpe:2.3:h:lexmark:cx31x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cx41x_firmware:*:*:*:*:*:*:*:* lw73.vy2.p263 (including)
cpe:2.3:h:lexmark:cx41x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:* lw73.gm2.p263 (including)
cpe:2.3:h:lexmark:cx310:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:ms310_firmware:*:*:*:*:*:*:*:* lw73.prl.p263 (including)
cpe:2.3:h:lexmark:ms310:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:ms312_firmware:*:*:*:*:*:*:*:* lw73.prl.p263 (including)
cpe:2.3:h:lexmark:ms312:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:ms317_firmware:*:*:*:*:*:*:*:* lw73.prl.p263 (including)
cpe:2.3:h:lexmark:ms317:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:ms410_firmware:*:*:*:*:*:*:*:* lw73.prl.p263 (including)
cpe:2.3:h:lexmark:ms410:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:m1140_firmware:*:*:*:*:*:*:*:* lw73.prl.p263 (including)