SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19772

Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices.

MEDIUM 5.4EPSS 0.65%

Does this matter?

Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.

Description

Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.65% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
lexmark/cs31x firmware · lexmark/cs41x firmware · lexmark/cs51x firmware · lexmark/cx310 firmware · lexmark/cx410 firmware · lexmark/xc2130 firmware · lexmark/cx510 firmware · lexmark/xc2132 firmware · lexmark/ms310 firmware · lexmark/ms312 firmware · lexmark/ms317 firmware · lexmark/ms410 firmware · lexmark/m1140 firmware · lexmark/ms315 firmware · lexmark/ms415 firmware · lexmark/ms417 firmware · lexmark/ms51x firmware · lexmark/ms610dn firmware · lexmark/ms617 firmware · lexmark/m1145 firmware · +40 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.