Lexmark C734 Firmware vulnerabilities

16 known vulnerabilities affecting lexmark/c734_firmware.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH3MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2021-44734CRITICALCVSS 9.8fixed in lr.sk.p8352022-01-20
CVE-2021-44734 [CRITICAL] CWE-94 CVE-2021-44734: Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which ca Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
nvd
CVE-2021-44738CRITICALCVSS 9.8fixed in lr.sk.p8352022-01-20
CVE-2021-44738 [CRITICAL] CWE-120 CVE-2021-44738: Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscrip Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
nvd
CVE-2021-44737HIGHCVSS 8.8fixed in lr.sk.p8352022-01-20
CVE-2021-44737 [HIGH] CWE-22 CVE-2021-44737: PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
nvd
CVE-2020-10094MEDIUMCVSS 5.4≤ lr.sk.p8242020-04-28
CVE-2020-10094 [MEDIUM] CWE-79 CVE-2020-10094: A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74. A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273; MS315, MS415, MS417 before LW74.TL2
nvd
CVE-2020-10093MEDIUMCVSS 5.4≤ lr.sk.p8242020-04-28
CVE-2020-10093 [MEDIUM] CWE-79 CVE-2020-10093: A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued pr A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
nvd
CVE-2011-3269HIGHCVSS 7.5≤ lr.sk.p5102020-03-09
CVE-2011-3269 [HIGH] CWE-200 CVE-2011-3269: Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitiv Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
nvd
CVE-2011-4538MEDIUMCVSS 5.3≤ lr.sk.p224a2020-03-09
CVE-2011-4538 [MEDIUM] CWE-200 CVE-2011-4538: Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
nvd
CVE-2019-19772MEDIUMCVSS 5.4≤ lr.sk.p8222020-03-06
CVE-2019-19772 [MEDIUM] CWE-79 CVE-2019-19772: Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexm Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
nvd
CVE-2019-19773MEDIUMCVSS 5.4≤ lr.sk.p8222020-03-06
CVE-2019-19773 [MEDIUM] CWE-79 CVE-2019-19773: Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
nvd
CVE-2019-18791MEDIUMCVSS 5.4≤ lr.sk.p8222020-02-13
CVE-2019-18791 [MEDIUM] CWE-79 CVE-2019-18791: Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
nvd
CVE-2019-9932CRITICALCVSS 9.8≤ lr.sk.p8152019-08-28
CVE-2019-9932 [CRITICAL] CWE-119 CVE-2019-9932: Various Lexmark products have a Buffer Overflow (issue 2 of 3). Various Lexmark products have a Buffer Overflow (issue 2 of 3).
nvd
CVE-2019-9930CRITICALCVSS 9.8≤ lr.sk.p8152019-08-28
CVE-2019-9930 [CRITICAL] CWE-190 CVE-2019-9930: Various Lexmark products have an Integer Overflow. Various Lexmark products have an Integer Overflow.
nvd
CVE-2019-9933CRITICALCVSS 9.8≤ lr.sk.p8152019-08-28
CVE-2019-9933 [CRITICAL] CWE-119 CVE-2019-9933: Various Lexmark products have a Buffer Overflow (issue 3 of 3). Various Lexmark products have a Buffer Overflow (issue 3 of 3).
nvd
CVE-2019-10058CRITICALCVSS 9.1≤ lr.sk.p8152019-08-28
CVE-2019-10058 [CRITICAL] CVE-2019-10058: Various Lexmark products have Incorrect Access Control. Various Lexmark products have Incorrect Access Control.
nvd
CVE-2019-9931HIGHCVSS 7.5≤ lr.sk.p8142019-08-28
CVE-2019-9931 [HIGH] CVE-2019-9931: Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be e Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
nvd
CVE-2019-10059MEDIUMCVSS 5.3≤ lr.sk.p8152019-08-28
CVE-2019-10059 [MEDIUM] CWE-254 CVE-2019-10059: The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices. The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
nvd