VYPR

M1145 Firmware

by Lexmark

CVEs (18)

  • CVE-2021-44734CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.06

    Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.

  • CVE-2021-44738CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

  • CVE-2019-9933CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 3 of 3).

  • CVE-2019-9932CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 2 of 3).

  • CVE-2019-9930CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have an Integer Overflow.

  • CVE-2019-10058CriAug 28, 2019
    risk 0.59cvss 9.1epss 0.01

    Various Lexmark products have Incorrect Access Control.

  • CVE-2021-44737HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

  • CVE-2023-40239HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.00

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…

  • CVE-2019-9931HigAug 28, 2019
    risk 0.49cvss 7.5epss 0.01

    Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.

  • CVE-2019-10057MedAug 28, 2019
    risk 0.42cvss 6.5epss 0.00

    Various Lexmark products have CSRF.

  • CVE-2020-10094MedApr 28, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before…

  • CVE-2020-10093MedApr 28, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.

  • CVE-2019-19773MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

  • CVE-2019-19772MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

  • CVE-2019-18791MedFeb 13, 2020
    risk 0.35cvss 5.4epss 0.01

    Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

  • CVE-2019-10059MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.

  • CVE-2019-9935MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 2 of 2).

  • CVE-2019-9934MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 1 of 2).