CVE-2019-19773
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
Affected (80)
Products: Lexmark: Cs31x Firmware, Cs41x Firmware, Cs51x Firmware, Cx310 Firmware, Cx410 Firmware, Xc2130 Firmware, Cx510 Firmware, Xc2132 Firmware, Ms310 Firmware, Ms312 Firmware, Ms317 Firmware, Ms410 Firmware, M1140 Firmware, Ms315 Firmware, Ms415 Firmware, Ms417 Firmware, Ms51x Firmware, Ms610dn Firmware, Ms617 Firmware, M1145 Firmware, M3150dn Firmware, Ms610de Firmware, M3150 Firmware, Ms71x Firmware, M5163dn Firmware, Ms810 Firmware, Ms811 Firmware, Ms812 Firmware, Ms817 Firmware, Ms818 Firmware, Ms810de Firmware, M5155 Firmware, M5163 Firmware, Ms812de Firmware, M5170 Firmware, Ms91x Firmware, Mx31x Firmware, Xm1135 Firmware, Mx410 Firmware, Mx510 Firmware, Mx511 Firmware, Xm1140 Firmware, Xm1145 Firmware, Mx610 Firmware, Mx611 Firmware, Xm3150 Firmware, Mx71x Firmware, Mx81x Firmware, Xm51xx Firmware, Xm71xx Firmware, Mx91x Firmware, Xm91x Firmware, Mx6500e Firmware, C746 Firmware, C748 Firmware, Cs748 Firmware, C792 Firmware, Cs796 Firmware, C925 Firmware, C950 Firmware, X548 Firmware, Xs548 Firmware, X74x Firmware, Xs748 Firmware, X792 Firmware, Xs79x Firmware, X925 Firmware, Xs925 Firmware, X95x Firmware, Xs95x Firmware, 6500e Firmware, C734 Firmware, C736 Firmware, E46x Firmware, T65x Firmware, X46x Firmware, X65x Firmware, X73x Firmware, W850 Firmware, X86x Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.vyl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cs31x | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.vy2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cs41x | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.vy4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cs51x | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.gm2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cx310 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.gm4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cx410 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.gm4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xc2130 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.gm7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cx510 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.gm7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xc2132 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.prl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms310 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.prl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms312 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.prl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms317 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.prl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms410 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.prl.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M1140 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tl2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms315 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tl2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms415 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tl2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms417 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms51x | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms610dn | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms617 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M1145 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M3150dn | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms610de | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.pr4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M3150 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms71x | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M5163dn | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms810 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms811 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms812 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms817 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms818 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms810de | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M5155 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M5163 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms812de | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.dn7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark M5170 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sa.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Ms91x | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx31x | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb2.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm1135 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx410 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx510 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx511 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm1140 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb4.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm1145 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx610 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx611 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.sb7.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm3150 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tu.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx71x | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tu.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx81x | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tu.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm51xx | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.tu.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm71xx | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.mg.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx91x | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.mg.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xm91x | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lw74.jd.p267 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Mx6500e | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.cm2.p731 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C746 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.cm4.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C748 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.cm4.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cs748 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.hc.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C792 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.hc.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Cs796 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.hv.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C925 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.tp.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C950 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.vk.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X548 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.vk.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xs548 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.ny.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X74x | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.ny.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xs748 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.mr.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X792 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.mr.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xs79x | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.hk.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X925 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.hk.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xs925 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.tq.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X95x | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.tq.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark Xs95x | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lhs60.jr.p735 |
| Running on/with | Platform Versions |
|---|---|
Lexmark 6500e | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.sk.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C734 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.ske.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark C736 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.lbh.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark E46x | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.jp.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark T65x | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.bs.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X46x | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.mn.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X65x | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lr.fl.p822 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X73x | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lp.jb.p821 |
| Running on/with | Platform Versions |
|---|---|
Lexmark W850 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to lp.sp.p821 |
| Running on/with | Platform Versions |
|---|---|
Lexmark X86x | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.