ID

VAR-202002-0319


CVE

CVE-2019-18791


TITLE

plural Lexmark Cross-site scripting vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-014608

DESCRIPTION

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser. plural Lexmark The product contains a cross-site scripting vulnerability.Information may be obtained and tampered with. Lexmark printers is a printer product from Lexmark. Lexmark printer MS812 and multiple previous series printers have cross-site scripting vulnerabilities. The vulnerability stems from the lack of proper validation of client data by web applications. An attacker could use this vulnerability to execute client code

Trust: 2.16

sources: NVD: CVE-2019-18791 // JVNDB: JVNDB-2019-014608 // CNVD: CNVD-2020-10499

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-10499

AFFECTED PRODUCTS

vendor:lexmarkmodel:xc2130scope:lteversion:lw73.gm4.p263

Trust: 1.0

vendor:lexmarkmodel:m3150scope:lteversion:lw73.pr4.p263

Trust: 1.0

vendor:lexmarkmodel:mx511scope:lteversion:lw73.sb4.p263

Trust: 1.0

vendor:lexmarkmodel:xs925scope:lteversion:lhs60.hk.p731

Trust: 1.0

vendor:lexmarkmodel:x65xscope:lteversion:lr.mn.p822

Trust: 1.0

vendor:lexmarkmodel:x74xscope:lteversion:lhs60.ny.p731

Trust: 1.0

vendor:lexmarkmodel:ms315scope:lteversion:lw73.tl2.p263

Trust: 1.0

vendor:lexmarkmodel:ms71xscope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:ms317scope:lteversion:lw73.prl.p263

Trust: 1.0

vendor:lexmarkmodel:mx410scope:lteversion:lw73.sb4.p263

Trust: 1.0

vendor:lexmarkmodel:x792scope:lteversion:lhs60.mr.p731

Trust: 1.0

vendor:lexmarkmodel:ms812descope:lteversion:lw73.dn7.p263

Trust: 1.0

vendor:lexmarkmodel:c734scope:lteversion:lr.sk.p822

Trust: 1.0

vendor:lexmarkmodel:ms51xscope:lteversion:lw73.pr2.p263

Trust: 1.0

vendor:lexmarkmodel:cx51xscope:lteversion:lw73.vy4.p263

Trust: 1.0

vendor:lexmarkmodel:xm71xxscope:lteversion:lw73.tu.p263

Trust: 1.0

vendor:lexmarkmodel:xs95xscope:lteversion:lhs60.tq.p731

Trust: 1.0

vendor:lexmarkmodel:xm1140scope:lteversion:lw73.sb4.p263

Trust: 1.0

vendor:lexmarkmodel:ms812scope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:e46xscope:lteversion:lr.lbh.p822

Trust: 1.0

vendor:lexmarkmodel:cx310scope:lteversion:lw73.gm2.p263

Trust: 1.0

vendor:lexmarkmodel:x925scope:lteversion:lhs60.hk.p731

Trust: 1.0

vendor:lexmarkmodel:cx31xscope:lteversion:lw73.vyl.p263

Trust: 1.0

vendor:lexmarkmodel:6500escope:lteversion:lhs60.jr.p731

Trust: 1.0

vendor:lexmarkmodel:ms410scope:lteversion:lw73.prl.p263

Trust: 1.0

vendor:lexmarkmodel:xs748scope:lteversion:lhs60.ny.p731

Trust: 1.0

vendor:lexmarkmodel:m3150dnscope:lteversion:lw73.pr2.p263

Trust: 1.0

vendor:lexmarkmodel:xc2132scope:lteversion:lw73.gm7.p263

Trust: 1.0

vendor:lexmarkmodel:mx611scope:lteversion:lw73.sb7.p263

Trust: 1.0

vendor:lexmarkmodel:cx410scope:lteversion:lw73.gm4.p263

Trust: 1.0

vendor:lexmarkmodel:m1145scope:lteversion:lw73.pr2.p263

Trust: 1.0

vendor:lexmarkmodel:m5170scope:lteversion:lw73.dn7.p263

Trust: 1.0

vendor:lexmarkmodel:cx510scope:lteversion:lw73.gm7.p263

Trust: 1.0

vendor:lexmarkmodel:ms811scope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:mx81xscope:lteversion:lw73.tu.p263

Trust: 1.0

vendor:lexmarkmodel:xm1145scope:lteversion:lw73.sb4.p263

Trust: 1.0

vendor:lexmarkmodel:cs796scope:lteversion:lhs60.hc.p731

Trust: 1.0

vendor:lexmarkmodel:c748scope:lteversion:lhs60.cm4.p731

Trust: 1.0

vendor:lexmarkmodel:ms817scope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:ms610dnscope:lteversion:lw73.pr2.p263

Trust: 1.0

vendor:lexmarkmodel:xs79xscope:lteversion:lhs60.mr.p731

Trust: 1.0

vendor:lexmarkmodel:ms610descope:lteversion:lw73.pr4.p263

Trust: 1.0

vendor:lexmarkmodel:mx610scope:lteversion:lw73.sb7.p263

Trust: 1.0

vendor:lexmarkmodel:c736scope:lteversion:lr.ske.p822

Trust: 1.0

vendor:lexmarkmodel:x86xscope:lteversion:lp.sp.p821

Trust: 1.0

vendor:lexmarkmodel:ms415scope:lteversion:lw73.tl2.p263

Trust: 1.0

vendor:lexmarkmodel:x46xscope:lteversion:lr.bs.p822

Trust: 1.0

vendor:lexmarkmodel:ms818scope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:x95xscope:lteversion:lhs60.tq.p731

Trust: 1.0

vendor:lexmarkmodel:ms91xscope:lteversion:lw73.sa.p263

Trust: 1.0

vendor:lexmarkmodel:c925scope:lteversion:lhs60.hv.p731

Trust: 1.0

vendor:lexmarkmodel:ms417scope:lteversion:lw73.tl2.p263

Trust: 1.0

vendor:lexmarkmodel:mx6500escope:lteversion:lw73.jd.p263

Trust: 1.0

vendor:lexmarkmodel:xm3150scope:lteversion:lw73.sb7.p263

Trust: 1.0

vendor:lexmarkmodel:cs748scope:lteversion:lhs60.cm4.p731

Trust: 1.0

vendor:lexmarkmodel:ms310scope:lteversion:lw73.prl.p263

Trust: 1.0

vendor:lexmarkmodel:mx71xscope:lteversion:lw73.tu.p263

Trust: 1.0

vendor:lexmarkmodel:x73xscope:lteversion:lr.fl.p822

Trust: 1.0

vendor:lexmarkmodel:m1140scope:lteversion:lw73.prl.p263

Trust: 1.0

vendor:lexmarkmodel:ms312scope:lteversion:lw73.prl.p263

Trust: 1.0

vendor:lexmarkmodel:mx31xscope:lteversion:lw73.sb2.p263

Trust: 1.0

vendor:lexmarkmodel:xs548scope:lteversion:lhs60.vk.p731

Trust: 1.0

vendor:lexmarkmodel:w850scope:lteversion:lp.jb.p821

Trust: 1.0

vendor:lexmarkmodel:c792scope:lteversion:lhs60.hc.p731

Trust: 1.0

vendor:lexmarkmodel:xm51xxscope:lteversion:lw73.tu.p263

Trust: 1.0

vendor:lexmarkmodel:m5155scope:lteversion:lw73.dn4.p263

Trust: 1.0

vendor:lexmarkmodel:c746scope:lteversion:lhs60.cm2.p731

Trust: 1.0

vendor:lexmarkmodel:m5163dnscope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:ms617scope:lteversion:lw73.pr2.p263

Trust: 1.0

vendor:lexmarkmodel:ms810descope:lteversion:lw73.dn4.p263

Trust: 1.0

vendor:lexmarkmodel:xm91xscope:lteversion:lw73.mg.p263

Trust: 1.0

vendor:lexmarkmodel:mx510scope:lteversion:lw73.sb4.p263

Trust: 1.0

vendor:lexmarkmodel:xm1135scope:lteversion:lw73.sb2.p263

Trust: 1.0

vendor:lexmarkmodel:ms810scope:lteversion:lw73.dn2.p263

Trust: 1.0

vendor:lexmarkmodel:c950scope:lteversion:lhs60.tp.p731

Trust: 1.0

vendor:lexmarkmodel:cx41xscope:lteversion:lw73.vy2.p263

Trust: 1.0

vendor:lexmarkmodel:m5163scope:lteversion:lw73.dn4.p263

Trust: 1.0

vendor:lexmarkmodel:mx91xscope:lteversion:lw73.mg.p263

Trust: 1.0

vendor:lexmarkmodel:x548scope:lteversion:lhs60.vk.p731

Trust: 1.0

vendor:lexmarkmodel:t65xscope:lteversion:lr.jp.p822

Trust: 1.0

vendor:lexmarkmodel:cx310scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:cx31xscope: - version: -

Trust: 0.8

vendor:lexmarkmodel:cx41xscope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms1140scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms310scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms312scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms315scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms317scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms410scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:ms415scope: - version: -

Trust: 0.8

vendor:lexmarkmodel:printer <=ms812scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-10499 // JVNDB: JVNDB-2019-014608 // NVD: CVE-2019-18791

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-18791
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2019-014608
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-10499
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202002-753
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2019-18791
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2019-014608
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-10499
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-18791
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.3
impactScore: 2.7
version: 3.1

Trust: 1.0

NVD: JVNDB-2019-014608
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-10499 // JVNDB: JVNDB-2019-014608 // CNNVD: CNNVD-202002-753 // NVD: CVE-2019-18791

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2019-014608 // NVD: CVE-2019-18791

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202002-753

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202002-753

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-014608

PATCH

title:Lexmark Security Advisoriesurl:https://support.lexmark.com/alerts/

Trust: 0.8

title:TE933url:http://support.lexmark.com/index?page=content&id=TE933&modifiedDate=02/04/20&actp=LIST_RECENT&userlocale=EN_US&locale=en

Trust: 0.8

title:Patch for Lexmark printer cross-site scripting vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/201923

Trust: 0.6

title:Lexmark printer Fixes for cross-site scripting vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=110214

Trust: 0.6

sources: CNVD: CNVD-2020-10499 // JVNDB: JVNDB-2019-014608 // CNNVD: CNNVD-202002-753

EXTERNAL IDS

db:NVDid:CVE-2019-18791

Trust: 3.0

db:JVNDBid:JVNDB-2019-014608

Trust: 0.8

db:CNVDid:CNVD-2020-10499

Trust: 0.6

db:CNNVDid:CNNVD-202002-753

Trust: 0.6

sources: CNVD: CNVD-2020-10499 // JVNDB: JVNDB-2019-014608 // CNNVD: CNNVD-202002-753 // NVD: CVE-2019-18791

REFERENCES

url:http://support.lexmark.com/alerts/

Trust: 2.2

url:http://support.lexmark.com/index?page=content&id=te933&modifieddate=02/04/20&actp=list_recent&userlocale=en_us&locale=en

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-18791

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-18791

Trust: 0.8

sources: CNVD: CNVD-2020-10499 // JVNDB: JVNDB-2019-014608 // CNNVD: CNNVD-202002-753 // NVD: CVE-2019-18791

SOURCES

db:CNVDid:CNVD-2020-10499
db:JVNDBid:JVNDB-2019-014608
db:CNNVDid:CNNVD-202002-753
db:NVDid:CVE-2019-18791

LAST UPDATE DATE

2024-11-23T22:51:30.369000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-10499date:2020-02-19T00:00:00
db:JVNDBid:JVNDB-2019-014608date:2020-03-04T00:00:00
db:CNNVDid:CNNVD-202002-753date:2023-05-22T00:00:00
db:NVDid:CVE-2019-18791date:2024-11-21T04:33:34.237

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-10499date:2020-02-19T00:00:00
db:JVNDBid:JVNDB-2019-014608date:2020-03-04T00:00:00
db:CNNVDid:CNNVD-202002-753date:2020-02-13T00:00:00
db:NVDid:CVE-2019-18791date:2020-02-13T16:15:11.993