Lexmark Ms610De Firmware vulnerabilities
11 known vulnerabilities affecting lexmark/ms610de_firmware.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2023-40239HIGHCVSS 7.5≤ lw80.pr4.p2452023-09-01
CVE-2023-40239 [HIGH] CWE-611 CVE-2023-40239: Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
nvd
CVE-2021-44734CRITICALCVSS 9.8fixed in lw80.pr4.p2102022-01-20
CVE-2021-44734 [CRITICAL] CWE-94 CVE-2021-44734: Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which ca
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
nvd
CVE-2021-44738CRITICALCVSS 9.8fixed in lw80.pr4.p2102022-01-20
CVE-2021-44738 [CRITICAL] CWE-120 CVE-2021-44738: Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscrip
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
nvd
CVE-2021-44737HIGHCVSS 8.8fixed in lw80.pr4.p2102022-01-20
CVE-2021-44737 [HIGH] CWE-22 CVE-2021-44737: PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
nvd
CVE-2020-10094MEDIUMCVSS 5.4≤ lw74.pr4.p2722020-04-28
CVE-2020-10094 [MEDIUM] CWE-79 CVE-2020-10094: A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before LW74.PRL.P273; MS410, M1140 before LW74.PRL.P273; MS315, MS415, MS417 before LW74.TL2
nvd
CVE-2020-10093MEDIUMCVSS 5.4≤ lw74.pr4.p2722020-04-28
CVE-2020-10093 [MEDIUM] CWE-79 CVE-2020-10093: A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued pr
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
nvd
CVE-2018-18894HIGHCVSS 7.5fixed in lw71.pr4.p2162020-03-10
CVE-2018-18894 [HIGH] CWE-22 CVE-2018-18894: Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal v
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
nvd
CVE-2019-19772MEDIUMCVSS 5.4≤ lw74.pr4.p2672020-03-06
CVE-2019-19772 [MEDIUM] CWE-79 CVE-2019-19772: Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexm
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
nvd
CVE-2019-19773MEDIUMCVSS 5.4≤ lw74.pr4.p2672020-03-06
CVE-2019-19773 [MEDIUM] CWE-79 CVE-2019-19773: Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
nvd
CVE-2019-18791MEDIUMCVSS 5.4≤ lw73.pr4.p2632020-02-13
CVE-2019-18791 [MEDIUM] CWE-79 CVE-2019-18791: Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
nvd
CVE-2019-10058CRITICALCVSS 9.1≤ lw71.pr4.p2292019-08-28
CVE-2019-10058 [CRITICAL] CVE-2019-10058: Various Lexmark products have Incorrect Access Control.
Various Lexmark products have Incorrect Access Control.
nvd