Home/CVE/A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo
CVE

CVE-2020-10094

A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo

A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273.

CS41x before LW74.VY2.P273.

CS51x before LW74.VY4.P273.

CX310 before LW74.GM2.P273.

CX410 & XC2130 before LW74.GM4.P273.

CX510 & XC2132 before LW74.GM7.P273.

MS310, MS312, MS317 before LW74.PRL.P273.

MS410, M1140 before LW74.PRL.P273.

MS315, MS415, MS417 before LW74.TL2.P273.

MS51x, MS610dn, MS617 before LW74.PR2.P273.

M1145, M3150dn before LW74.PR2.P273.

MS610de, M3150 before LW74.PR4.P273.

MS71x,M5163dn before LW74.DN2.P273.

MS810, MS811, MS812, MS817, MS818 before LW74.DN2.P273.

MS810de, M5155, M5163 before LW74.DN4.P273.

MS812de, M5170 before LW74.DN7.P273.

MS91x before LW74.SA.P273.

MX31x, XM1135 before LW74.SB2.P273.

MX410, MX510 & MX511 before LW74.SB4.P273.

XM1140, XM1145 before LW74.SB4.P273.

MX610 & MX611 before LW74.SB7.P273.

XM3150 before LW74.SB7.P273.

MX71x, MX81x before LW74.TU.P273.

XM51xx & XM71xx before LW74.TU.P273.

MX91x & XM91x before LW74.MG.P273.

MX6500e before LW74.JD.P273.

C746 before LHS60.CM2.P738.

C748, CS748 before LHS60.CM4.P738.

C792, CS796 before LHS60.HC.P738.

C925 before LHS60.HV.P738.

C950 before LHS60.TP.P738.

X548 & XS548 before LHS60.VK.P738.

X74x & XS748 before LHS60.NY.P738.

X792 & XS79x before LHS60.MR.P738.

X925 & XS925 before LHS60.HK.P738.

X95x & XS95x before LHS60.TQ.P738.

6500e before LHS60.JR.P738;C734 LR.SK.P824 and earlier.

C736 LR.SKE.P824 and earlier.

E46x LR.LBH.P824 and earlier.

T65x LR.JP.P824 and earlier.

X46x LR.BS.P824 and earlier.

X65x LR.MN.P824 and earlier.

X73x LR.FL.P824 and earlier.

W850 LP.JB.P823 and earlier.

and X86x LP.SP.P823 and earlier.

MEDIUM · CVSS 5.4 EPSS 0.00352
Monitor
  • No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0 YARA rules0

Affected Products & Versions

60
lexmark cs31x firmware<= lw74.vyl.p272
lexmark cs41x firmware<= lw74.vy2.p272
lexmark cs51x firmware<= lw74.vy4.p272
lexmark cx310 firmware<= lw74.gm2.p272
lexmark cx410 firmware<= lw74.gm4.p272
lexmark xc2130 firmware<= lw74.gm4.p272
lexmark cx510 firmware<= lw74.gm7.p272
lexmark xc2132 firmware<= lw74.gm7.p272

Scoring & Timeline

5.4
MEDIUM · CVSS v3.1 · cve@mitre.org
View on NVD
Attack Vector
Network Adjacent Local Physical
Attack Complexity
Low High
Privileges Required
None Low High
User Interaction
None Required
Scope
Unchanged Changed
Confidentiality
None Low High
Integrity
None Low High
Availability
None Low High
Published to NVD28 Apr 2020 · 02:15 PM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
🔗

References & Sources

1
Source URLs (vendor pages, mailing lists, write-ups). Exploit/PoC links are in their own section above to avoid duplication.
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin