ID

VAR-201906-0822


CVE

CVE-2018-15520


TITLE

plural Lexmark Device buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-015803

DESCRIPTION

Various Lexmark devices have a Buffer Overflow (issue 2 of 2). plural Lexmark The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Lexmark CX82x and so on are a multi-function printer of American Lexmark (Lexmark). A buffer error vulnerability exists in several Lexmark products. This vulnerability stems from the incorrect verification of data boundaries when the network system or product performs operations on the memory, resulting in incorrect read and write operations to other associated memory locations. The following products and versions are affected: Lexmark CX82x CXTPP.052.024 and earlier, versions 052.200 to 052.204; CX860 CXTPP.052.024 and earlier, versions 052.200 to 052.204; XC6152 CXTPP.052.024 and earlier, versions 052.200 to 052.204 XC8155 CXTPP.052.024 and earlier, version 052.200 to 052.204; XC8160 CXTPP.052.024 and earlier, version 052.200 to 052.204; CX72x CXTAT.052.024 and earlier, version 052.200 to 052.204 and earlier; XC41x0 CX Version 052.200 to Version 052.204; CX92x, etc

Trust: 1.8

sources: NVD: CVE-2018-15520 // JVNDB: JVNDB-2018-015803 // VULHUB: VHN-125788 // VULMON: CVE-2018-15520

AFFECTED PRODUCTS

vendor:lexmarkmodel:cx62xscope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:mc2640scope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mx52xscope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:mx82xscope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:xc4240scope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mb2338scope:lteversion:mxngm.052.024

Trust: 1.0

vendor:lexmarkmodel:mb2770scope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:mx321scope:lteversion:mxngm.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2442scope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:xc8155scope:lteversion:cxtpp.052.024

Trust: 1.0

vendor:lexmarkmodel:mx52xscope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:xc6152scope:lteversion:cxtpp.052.024

Trust: 1.0

vendor:lexmarkmodel:xm7355scope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:cx522scope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mb2650scope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:cx860scope:gteversion:cxtpp.052.200

Trust: 1.0

vendor:lexmarkmodel:mb2770scope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:mx72xscope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:mx82xscope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2338scope:gteversion:mxngm.052.200

Trust: 1.0

vendor:lexmarkmodel:cx92xscope:gteversion:cxtmh.052.200

Trust: 1.0

vendor:lexmarkmodel:xc92x5scope:gteversion:cxtmh.052.200

Trust: 1.0

vendor:lexmarkmodel:xm124xscope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:xm7370scope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:cx421scope:lteversion:cxnzj.052.024

Trust: 1.0

vendor:lexmarkmodel:xc4240scope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:mx622scope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2650scope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2425scope:lteversion:cxnzj.052.024

Trust: 1.0

vendor:lexmarkmodel:xm124xscope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:xm3250scope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:cx72xscope:lteversion:cxtat.052.204

Trust: 1.0

vendor:lexmarkmodel:xc8160scope:gteversion:cxtpp.052.200

Trust: 1.0

vendor:lexmarkmodel:cx72xscope:lteversion:cxtat.052.024

Trust: 1.0

vendor:lexmarkmodel:mb2546scope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:mx72xscope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2770scope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:cx522scope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:cx522scope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mx622scope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:cx860scope:lteversion:cxtpp.052.204

Trust: 1.0

vendor:lexmarkmodel:mx42xscope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:cx82xscope:gteversion:cxtpp.052.200

Trust: 1.0

vendor:lexmarkmodel:mx52xscope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:xc8155scope:gteversion:cxtpp.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2325scope:lteversion:cxnzj.052.024

Trust: 1.0

vendor:lexmarkmodel:mx42xscope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:cx82xscope:lteversion:cxtpp.052.024

Trust: 1.0

vendor:lexmarkmodel:xc8160scope:lteversion:cxtpp.052.204

Trust: 1.0

vendor:lexmarkmodel:cx62xscope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mc2535scope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mx72xscope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:xc2235scope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:xc6152scope:gteversion:cxtpp.052.200

Trust: 1.0

vendor:lexmarkmodel:xc2235scope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mc2640scope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:xc92x5scope:lteversion:cxtmh.052.024

Trust: 1.0

vendor:lexmarkmodel:mb2442scope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:xm124xscope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2546scope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:cx82xscope:lteversion:cxtpp.052.204

Trust: 1.0

vendor:lexmarkmodel:cx421scope:gteversion:cxnzj.052.200

Trust: 1.0

vendor:lexmarkmodel:xc92x5scope:lteversion:cxtmh.052.204

Trust: 1.0

vendor:lexmarkmodel:cx92xscope:lteversion:cxtmh.052.024

Trust: 1.0

vendor:lexmarkmodel:mx321scope:lteversion:mxngm.052.024

Trust: 1.0

vendor:lexmarkmodel:xm3250scope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:xc4240scope:lteversion:cxtzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2546scope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:cx860scope:lteversion:cxtpp.052.024

Trust: 1.0

vendor:lexmarkmodel:xc41x0scope:lteversion:cxtat.052.024

Trust: 1.0

vendor:lexmarkmodel:xc41x0scope:lteversion:cxtat.052.204

Trust: 1.0

vendor:lexmarkmodel:cx92xscope:lteversion:cxtmh.052.204

Trust: 1.0

vendor:lexmarkmodel:xc41x0scope:gteversion:cxtat.052.200

Trust: 1.0

vendor:lexmarkmodel:xc8155scope:lteversion:cxtpp.052.204

Trust: 1.0

vendor:lexmarkmodel:mx321scope:gteversion:mxngm.052.200

Trust: 1.0

vendor:lexmarkmodel:xc6152scope:lteversion:cxtpp.052.204

Trust: 1.0

vendor:lexmarkmodel:cx72xscope:gteversion:cxtat.052.200

Trust: 1.0

vendor:lexmarkmodel:mb2650scope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:xm7355scope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:cx421scope:lteversion:cxnzj.052.204

Trust: 1.0

vendor:lexmarkmodel:xm3250scope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2425scope:gteversion:cxnzj.052.200

Trust: 1.0

vendor:lexmarkmodel:xm5370scope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:xc2235scope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2640scope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mx82xscope:gteversion:mxtgw.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2425scope:lteversion:cxnzj.052.204

Trust: 1.0

vendor:lexmarkmodel:mb2442scope:lteversion:mxtgm.052.204

Trust: 1.0

vendor:lexmarkmodel:xm7370scope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:mx622scope:lteversion:mxtgm.052.024

Trust: 1.0

vendor:lexmarkmodel:xc8160scope:lteversion:cxtpp.052.024

Trust: 1.0

vendor:lexmarkmodel:xm5370scope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:cx62xscope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2535scope:gteversion:cxtzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mx42xscope:gteversion:mxtgm.052.200

Trust: 1.0

vendor:lexmarkmodel:mc2325scope:gteversion:cxnzj.052.200

Trust: 1.0

vendor:lexmarkmodel:mb2338scope:lteversion:mxngm.052.204

Trust: 1.0

vendor:lexmarkmodel:xm7355scope:lteversion:mxtgw.052.024

Trust: 1.0

vendor:lexmarkmodel:xm7370scope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:mc2325scope:lteversion:cxnzj.052.204

Trust: 1.0

vendor:lexmarkmodel:xm5370scope:lteversion:mxtgw.052.204

Trust: 1.0

vendor:lexmarkmodel:mc2535scope:lteversion:cxtzj.052.024

Trust: 1.0

vendor:lexmarkmodel:cx72scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:cx82scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:cx860scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:cx92scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:mx321scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:xc41x0scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:xc6152scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:xc8155scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:xc8160scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:xc92x5scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-015803 // NVD: CVE-2018-15520

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15520
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-15520
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201906-1100
value: CRITICAL

Trust: 0.6

VULHUB: VHN-125788
value: HIGH

Trust: 0.1

VULMON: CVE-2018-15520
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-15520
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-125788
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15520
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-125788 // VULMON: CVE-2018-15520 // JVNDB: JVNDB-2018-015803 // CNNVD: CNNVD-201906-1100 // NVD: CVE-2018-15520

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-125788 // JVNDB: JVNDB-2018-015803 // NVD: CVE-2018-15520

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201906-1100

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201906-1100

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015803

PATCH

title:TE892url:http://support.lexmark.com/index?page=content&id=TE892&locale=en&userlocale=EN_US

Trust: 0.8

title:Multiple Lexmark Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=94201

Trust: 0.6

sources: JVNDB: JVNDB-2018-015803 // CNNVD: CNNVD-201906-1100

EXTERNAL IDS

db:NVDid:CVE-2018-15520

Trust: 2.6

db:JVNDBid:JVNDB-2018-015803

Trust: 0.8

db:CNNVDid:CNNVD-201906-1100

Trust: 0.7

db:VULHUBid:VHN-125788

Trust: 0.1

db:VULMONid:CVE-2018-15520

Trust: 0.1

sources: VULHUB: VHN-125788 // VULMON: CVE-2018-15520 // JVNDB: JVNDB-2018-015803 // CNNVD: CNNVD-201906-1100 // NVD: CVE-2018-15520

REFERENCES

url:http://support.lexmark.com/index?page=content&id=te892

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-15520

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15520

Trust: 0.8

url:http://support.lexmark.com/index?page=content&id=te892

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-125788 // VULMON: CVE-2018-15520 // JVNDB: JVNDB-2018-015803 // CNNVD: CNNVD-201906-1100 // NVD: CVE-2018-15520

SOURCES

db:VULHUBid:VHN-125788
db:VULMONid:CVE-2018-15520
db:JVNDBid:JVNDB-2018-015803
db:CNNVDid:CNNVD-201906-1100
db:NVDid:CVE-2018-15520

LAST UPDATE DATE

2024-11-23T22:41:29.168000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-125788date:2019-07-05T00:00:00
db:VULMONid:CVE-2018-15520date:2019-07-05T00:00:00
db:JVNDBid:JVNDB-2018-015803date:2019-07-08T00:00:00
db:CNNVDid:CNNVD-201906-1100date:2019-07-08T00:00:00
db:NVDid:CVE-2018-15520date:2024-11-21T03:51:00.073

SOURCES RELEASE DATE

db:VULHUBid:VHN-125788date:2019-06-28T00:00:00
db:VULMONid:CVE-2018-15520date:2019-06-28T00:00:00
db:JVNDBid:JVNDB-2018-015803date:2019-07-08T00:00:00
db:CNNVDid:CNNVD-201906-1100date:2019-06-28T00:00:00
db:NVDid:CVE-2018-15520date:2019-06-28T16:15:09.463