CVE-2019-18791

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lexmark:cx31x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx31x:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lexmark:cx41x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx41x:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx310:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:lexmark:ms310_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms310:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:lexmark:ms312_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms312:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:lexmark:ms317_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms317:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:lexmark:ms410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms410:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:lexmark:m1140_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m1140:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:lexmark:ms315_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms315:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:lexmark:ms415_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms415:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:lexmark:ms417_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms417:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:lexmark:ms51x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms51x:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:lexmark:ms610dn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms610dn:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:lexmark:ms617_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms617:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:lexmark:m1145_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m1145:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:lexmark:m3150dn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m3150dn:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:lexmark:ms71x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms71x:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:lexmark:m5163dn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m5163dn:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:lexmark:ms810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms810:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:lexmark:ms811_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms811:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:lexmark:ms812_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms812:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:lexmark:ms817_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms817:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:lexmark:ms818_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms818:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:lexmark:ms810de_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms810de:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:lexmark:m5155_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m5155:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:lexmark:m5163_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m5163:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:lexmark:ms812de_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms812de:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:lexmark:m5170_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m5170:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:lexmark:ms91x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms91x:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:lexmark:mx31x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx31x:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:lexmark:xm1135_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm1135:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:lexmark:mx410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx410:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:lexmark:mx510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx510:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:lexmark:mx511_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx511:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:lexmark:mx610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx610:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:lexmark:mx611_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx611:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:lexmark:xm3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm3150:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:lexmark:mx71x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx71x:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:lexmark:mx81x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx81x:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:lexmark:xm51xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm51xx:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:lexmark:xm71xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm71xx:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:lexmark:mx91x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx91x:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:lexmark:xm91x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm91x:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:lexmark:mx6500e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:mx6500e:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:lexmark:c746_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c746:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:lexmark:c748_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c748:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:lexmark:cs748_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cs748:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:lexmark:c792_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c792:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:lexmark:cs796_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cs796:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:lexmark:c925_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c925:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:lexmark:c950_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c950:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:lexmark:x548_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x548:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:lexmark:xs548_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xs548:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:lexmark:x74x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x74x:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:lexmark:xs748_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xs748:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:lexmark:x792_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x792:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:lexmark:xs79x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xs79x:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:lexmark:x925_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x925:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:lexmark:xs925_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xs925:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:lexmark:x95x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x95x:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:lexmark:xs95x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xs95x:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:lexmark:6500e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:6500e:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:lexmark:c734_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c734:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:lexmark:c736_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:c736:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:lexmark:e46x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:e46x:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:lexmark:t65x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:t65x:-:*:*:*:*:*:*:*

Configuration 67 (hide)

AND
cpe:2.3:o:lexmark:x46x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x46x:-:*:*:*:*:*:*:*

Configuration 68 (hide)

AND
cpe:2.3:o:lexmark:x65x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x65x:-:*:*:*:*:*:*:*

Configuration 69 (hide)

AND
cpe:2.3:o:lexmark:x73x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x73x:-:*:*:*:*:*:*:*

Configuration 70 (hide)

AND
cpe:2.3:o:lexmark:w850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:w850:-:*:*:*:*:*:*:*

Configuration 71 (hide)

AND
cpe:2.3:o:lexmark:x86x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:x86x:-:*:*:*:*:*:*:*

Configuration 72 (hide)

AND
cpe:2.3:o:lexmark:cx410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx410:-:*:*:*:*:*:*:*

Configuration 73 (hide)

AND
cpe:2.3:o:lexmark:xc2130_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc2130:-:*:*:*:*:*:*:*

Configuration 74 (hide)

AND
cpe:2.3:o:lexmark:cx510_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx510:-:*:*:*:*:*:*:*

Configuration 75 (hide)

AND
cpe:2.3:o:lexmark:xc2132_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xc2132:-:*:*:*:*:*:*:*

Configuration 76 (hide)

AND
cpe:2.3:o:lexmark:cx51x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:cx51x:-:*:*:*:*:*:*:*

Configuration 77 (hide)

AND
cpe:2.3:o:lexmark:ms610de_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:ms610de:-:*:*:*:*:*:*:*

Configuration 78 (hide)

AND
cpe:2.3:o:lexmark:m3150_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:m3150:-:*:*:*:*:*:*:*

Configuration 79 (hide)

AND
cpe:2.3:o:lexmark:xm1140_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm1140:-:*:*:*:*:*:*:*

Configuration 80 (hide)

AND
cpe:2.3:o:lexmark:xm1145_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:lexmark:xm1145:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:33

Type Values Removed Values Added
References () http://support.lexmark.com/alerts/ - Vendor Advisory () http://support.lexmark.com/alerts/ - Vendor Advisory
References () http://support.lexmark.com/index?page=content&id=TE933&modifiedDate=02/04/20&actp=LIST_RECENT&userlocale=EN_US&locale=en - Vendor Advisory () http://support.lexmark.com/index?page=content&id=TE933&modifiedDate=02/04/20&actp=LIST_RECENT&userlocale=EN_US&locale=en - Vendor Advisory

Information

Published : 2020-02-13 16:15

Updated : 2024-11-21 04:33


NVD link : CVE-2019-18791

Mitre link : CVE-2019-18791

CVE.ORG link : CVE-2019-18791


JSON object : View

Products Affected

lexmark

  • x925
  • x46x_firmware
  • xm91x_firmware
  • mx81x
  • cx31x_firmware
  • ms811
  • ms71x_firmware
  • x65x
  • ms417_firmware
  • ms310
  • xs95x_firmware
  • cx310_firmware
  • ms812de
  • ms91x
  • xs548_firmware
  • x95x
  • w850_firmware
  • xc2130_firmware
  • mx510
  • xm51xx_firmware
  • c746_firmware
  • xs79x_firmware
  • ms811_firmware
  • x548
  • mx91x_firmware
  • m5163dn_firmware
  • ms818
  • m5163_firmware
  • x792
  • m5163dn
  • c925_firmware
  • ms810de_firmware
  • ms312
  • c950
  • x65x_firmware
  • cx510
  • ms51x_firmware
  • cx310
  • x46x
  • mx610_firmware
  • ms317_firmware
  • cs748
  • m1145_firmware
  • xs79x
  • m5155
  • e46x
  • x86x_firmware
  • mx511
  • w850
  • xc2130
  • ms610dn_firmware
  • 6500e
  • ms415
  • cx410_firmware
  • ms610dn
  • m5155_firmware
  • m5163
  • xs925_firmware
  • mx611_firmware
  • cx51x
  • cx31x
  • xm71xx_firmware
  • cs796_firmware
  • ms71x
  • xm71xx
  • x73x_firmware
  • xs95x
  • cx410
  • xm91x
  • cs748_firmware
  • xs548
  • ms812_firmware
  • mx510_firmware
  • mx410_firmware
  • c746
  • xm1135_firmware
  • c792_firmware
  • m1140
  • x925_firmware
  • xm1140_firmware
  • mx410
  • x792_firmware
  • x74x
  • ms51x
  • ms610de
  • ms810de
  • mx81x_firmware
  • c925
  • xc2132_firmware
  • cx51x_firmware
  • ms810
  • xm1135
  • xs748
  • mx6500e_firmware
  • c792
  • c734
  • m1140_firmware
  • c736_firmware
  • ms617_firmware
  • mx71x_firmware
  • ms818_firmware
  • xs748_firmware
  • ms310_firmware
  • xs925
  • ms315
  • mx511_firmware
  • c748_firmware
  • ms610de_firmware
  • xm1145
  • m3150
  • m3150dn_firmware
  • xm1140
  • c748
  • ms417
  • mx71x
  • cx41x_firmware
  • m5170_firmware
  • ms812
  • e46x_firmware
  • x86x
  • ms315_firmware
  • ms312_firmware
  • ms817_firmware
  • xm3150
  • mx610
  • 6500e_firmware
  • ms317
  • xm51xx
  • c736
  • ms410
  • mx6500e
  • m5170
  • c734_firmware
  • x95x_firmware
  • ms812de_firmware
  • c950_firmware
  • x73x
  • ms817
  • m3150dn
  • t65x_firmware
  • ms91x_firmware
  • m3150_firmware
  • ms810_firmware
  • mx31x
  • ms410_firmware
  • ms415_firmware
  • t65x
  • ms617
  • cx41x
  • cs796
  • x548_firmware
  • mx91x
  • x74x_firmware
  • cx510_firmware
  • mx611
  • mx31x_firmware
  • xm1145_firmware
  • xc2132
  • xm3150_firmware
  • m1145
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')