devices
by Lexmark
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26070 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4). | ||
| CVE-2023-26069 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4). | ||
| CVE-2023-26066 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index. | ||
| CVE-2023-26065 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have an Integer Overflow. | ||
| CVE-2023-26064 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write. | ||
| CVE-2023-26063 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type. | ||
| CVE-2021-44736 | Cri | 0.64 | 9.8 | 0.02 | Jan 20, 2022 | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature. | ||
| CVE-2021-44735 | Cri | 0.64 | 9.8 | 0.08 | Jan 20, 2022 | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. | ||
| CVE-2021-44734 | Cri | 0.64 | 9.8 | 0.06 | Jan 20, 2022 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. | ||
| CVE-2021-44738 | Cri | 0.64 | 9.8 | 0.03 | Jan 20, 2022 | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. | ||
| CVE-2018-15519 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2019 | Various Lexmark devices have a Buffer Overflow (issue 1 of 2). | ||
| CVE-2018-15520 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2019 | Various Lexmark devices have a Buffer Overflow (issue 2 of 2). | ||
| CVE-2023-50735 | Cri | 0.59 | 9.0 | 0.01 | Feb 28, 2024 | A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code. | ||
| CVE-2021-44737 | Hig | 0.57 | 8.8 | 0.01 | Jan 20, 2022 | PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files. | ||
| CVE-2023-26067 | Hig | 0.56 | 8.1 | 0.38 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | ||
| CVE-2020-10095 | Hig | 0.53 | 8.1 | 0.00 | Feb 19, 2025 | Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device. | ||
| CVE-2022-29850 | Hig | 0.53 | 8.1 | 0.01 | Aug 26, 2022 | Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots. | ||
| CVE-2023-40239 | Hig | 0.49 | 7.5 | 0.00 | Sep 1, 2023 | Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or… | ||
| CVE-2024-11344 | Hig | 0.47 | 7.3 | 0.00 | Feb 13, 2025 | A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code. | ||
| CVE-2025-65081 | Med | 0.45 | — | 0.01 | Feb 3, 2026 | An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user. |
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
- risk 0.64cvss 9.8epss 0.02
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
- risk 0.64cvss 9.8epss 0.08
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
- risk 0.64cvss 9.8epss 0.06
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
- risk 0.64cvss 9.8epss 0.03
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
- risk 0.64cvss 9.8epss 0.01
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
- risk 0.64cvss 9.8epss 0.01
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
- risk 0.59cvss 9.0epss 0.01
A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
- risk 0.56cvss 8.1epss 0.38
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
- risk 0.53cvss 8.1epss 0.00
Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.
- risk 0.53cvss 8.1epss 0.01
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
- risk 0.49cvss 7.5epss 0.00
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…
- risk 0.47cvss 7.3epss 0.00
A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- risk 0.45cvss —epss 0.01
An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
Page 1 of 2