CVE-2019-19772

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/03/2020
Last modified:
09/03/2020

Description

Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lexmark:cs31x_firmware:*:*:*:*:*:*:*:* lw74.vyl.p267 (including)
cpe:2.3:h:lexmark:cs31x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cs41x_firmware:*:*:*:*:*:*:*:* lw74.vy2.p267 (including)
cpe:2.3:h:lexmark:cs41x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cs51x_firmware:*:*:*:*:*:*:*:* lw74.vy4.p267 (including)
cpe:2.3:h:lexmark:cs51x:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:* lw74.gm2.p267 (including)
cpe:2.3:h:lexmark:cx310:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cx410_firmware:*:*:*:*:*:*:*:* lw74.gm4.p267 (including)
cpe:2.3:h:lexmark:cx410:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:xc2130_firmware:*:*:*:*:*:*:*:* lw74.gm4.p267 (including)
cpe:2.3:h:lexmark:xc2130:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:cx510_firmware:*:*:*:*:*:*:*:* lw74.gm7.p267 (including)
cpe:2.3:h:lexmark:cx510:-:*:*:*:*:*:*:*
cpe:2.3:o:lexmark:xc2132_firmware:*:*:*:*:*:*:*:* lw74.gm7.p267 (including)