CVE-2019-18791
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
13/02/2020
Last modified:
20/02/2020
Description
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lexmark:cx31x_firmware:*:*:*:*:*:*:*:* | lw73.vyl.p263 (including) | |
| cpe:2.3:h:lexmark:cx31x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:cx41x_firmware:*:*:*:*:*:*:*:* | lw73.vy2.p263 (including) | |
| cpe:2.3:h:lexmark:cx41x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:* | lw73.gm2.p263 (including) | |
| cpe:2.3:h:lexmark:cx310:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:ms310_firmware:*:*:*:*:*:*:*:* | lw73.prl.p263 (including) | |
| cpe:2.3:h:lexmark:ms310:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:ms312_firmware:*:*:*:*:*:*:*:* | lw73.prl.p263 (including) | |
| cpe:2.3:h:lexmark:ms312:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:ms317_firmware:*:*:*:*:*:*:*:* | lw73.prl.p263 (including) | |
| cpe:2.3:h:lexmark:ms317:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:ms410_firmware:*:*:*:*:*:*:*:* | lw73.prl.p263 (including) | |
| cpe:2.3:h:lexmark:ms410:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lexmark:m1140_firmware:*:*:*:*:*:*:*:* | lw73.prl.p263 (including) |
To consult the complete list of CPE names with products and versions, see this page



