Home/Product/lexmark xm1140 firmware
Product

lexmark xm1140 firmware

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-40239
<= lw80.sb4.p245
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware
7.5HIGH
CVE-2021-44737
< lw80.sb4.p210
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configurat
8.8HIGH
CVE-2021-44734
< lw80.sb4.p210
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote cod
9.8CRITICAL
CVE-2021-44738
< lw80.sb4.p210
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
9.8CRITICAL
CVE-2020-10094
<= lw74.sb4.p272
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY
5.4MEDIUM
CVE-2020-10093
<= lw74.sb4.p272
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
5.4MEDIUM
CVE-2019-19773
<= lw74.sb4.p267
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products ar
5.4MEDIUM
CVE-2019-19772
<= lw74.sb4.p267
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products
5.4MEDIUM
CVE-2019-18791
<= lw73.sb4.p263
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. Th
5.4MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin