CVE-2018-15520
published 2019-06-28CVE-2018-15520: Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.19%
64.3th percentile
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lexmark | cx421_firmware | <= cxnzj.052.024 | — |
| lexmark | cx421_firmware | cxnzj.052.200 – cxnzj.052.204 | — |
| lexmark | cx522_firmware | <= cxtzj.052.024 | — |
| lexmark | cx522_firmware | cxtzj.052.200 – cxtzj.052.204 | — |
| lexmark | cx62x_firmware | <= cxtzj.052.024 | — |
| lexmark | cx62x_firmware | cxtzj.052.200 – cxtzj.052.204 | — |
| lexmark | cx72x_firmware | <= cxtat.052.024 | — |
| lexmark | cx72x_firmware | cxtat.052.200 – cxtat.052.204 | — |
| lexmark | cx82x_firmware | <= cxtpp.052.024 | — |
| lexmark | cx82x_firmware | cxtpp.052.200 – cxtpp.052.204 | — |
| lexmark | cx860_firmware | <= cxtpp.052.024 | — |
| lexmark | cx860_firmware | cxtpp.052.200 – cxtpp.052.204 | — |
| lexmark | cx92x_firmware | <= cxtmh.052.024 | — |
| lexmark | cx92x_firmware | cxtmh.052.200 – cxtmh.052.204 | — |
| lexmark | mb2338_firmware | <= mxngm.052.024 | — |
| lexmark | mb2338_firmware | mxngm.052.200 – mxngm.052.204 | — |
| lexmark | mb2442_firmware | <= mxtgm.052.024 | — |
| lexmark | mb2442_firmware | mxtgm.052.200 – mxtgm.052.204 | — |
| lexmark | mb2546_firmware | <= mxtgm.052.024 | — |
| lexmark | mb2546_firmware | mxtgm.052.200 – mxtgm.052.204 | — |
| lexmark | mb2650_firmware | <= mxtgm.052.024 | — |
| lexmark | mb2650_firmware | mxtgm.052.200 – mxtgm.052.204 | — |
| lexmark | mb2770_firmware | <= mxtgw.052.024 | — |
| lexmark | mb2770_firmware | mxtgw.052.200 – mxtgw.052.204 | — |
| lexmark | mc2325_firmware | <= cxnzj.052.024 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-28
Published