CVE-2019-19773
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
06/03/2020
Last modified:
09/03/2020
Description
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:lexmark:cs31x_firmware:*:*:*:*:*:*:*:* | lw74.vyl.p267 (including) | |
cpe:2.3:h:lexmark:cs31x:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:cs41x_firmware:*:*:*:*:*:*:*:* | lw74.vy2.p267 (including) | |
cpe:2.3:h:lexmark:cs41x:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:cs51x_firmware:*:*:*:*:*:*:*:* | lw74.vy4.p267 (including) | |
cpe:2.3:h:lexmark:cs51x:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:* | lw74.gm2.p267 (including) | |
cpe:2.3:h:lexmark:cx310:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:cx410_firmware:*:*:*:*:*:*:*:* | lw74.gm4.p267 (including) | |
cpe:2.3:h:lexmark:cx410:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:xc2130_firmware:*:*:*:*:*:*:*:* | lw74.gm4.p267 (including) | |
cpe:2.3:h:lexmark:xc2130:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:cx510_firmware:*:*:*:*:*:*:*:* | lw74.gm7.p267 (including) | |
cpe:2.3:h:lexmark:cx510:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:lexmark:xc2132_firmware:*:*:*:*:*:*:*:* | lw74.gm7.p267 (including) |
To consult the complete list of CPE names with products and versions, see this page