MEDIUM · 5.4

CVE-2019-18791

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and oth...

Vulnerability Description

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
LexmarkCx31X Firmware<= lw73.vyl.p263
LexmarkCx31X-
LexmarkCx41X Firmware<= lw73.vy2.p263
LexmarkCx41X-
LexmarkCx310 Firmware<= lw73.gm2.p263
LexmarkCx310-
LexmarkMs310 Firmware<= lw73.prl.p263
LexmarkMs310-
LexmarkMs312 Firmware<= lw73.prl.p263
LexmarkMs312-
LexmarkMs317 Firmware<= lw73.prl.p263
LexmarkMs317-
LexmarkMs410 Firmware<= lw73.prl.p263
LexmarkMs410-
LexmarkM1140 Firmware<= lw73.prl.p263
LexmarkM1140-
LexmarkMs315 Firmware<= lw73.tl2.p263
LexmarkMs315-
LexmarkMs415 Firmware<= lw73.tl2.p263
LexmarkMs415-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-18791?

CVE-2019-18791 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and oth...

How severe is CVE-2019-18791?

CVE-2019-18791 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-18791?

Check the references section above for vendor advisories and patch information. Affected products include: Lexmark Cx31X Firmware, Lexmark Cx31X, Lexmark Cx41X Firmware, Lexmark Cx41X, Lexmark Cx310 Firmware.