CVE-2018-18894
HIGHCVSS 7.5/10EPSS 1.65%
Last modified
CVE-2018-18894 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.. EPSS estimates a 1.65% chance of exploitation in the next 30 days.
Description
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lexmark | 6500e Firmware | < lhs60.jr.p683 |
| Lexmark | C748 Firmware | < lhs60.cm4.p683 |
| Lexmark | C79x Firmware | < lhs60.hc.p683 |
| Lexmark | C925 Firmware | < lhs60.hv.p683 |
| Lexmark | C95x Firmware | < lhs60.tp.p683 |
| Lexmark | Cs41x Firmware | < lw71.vy2.p216 |
| Lexmark | Cs51x Firmware | < lw71.vy4.p216 |
| Lexmark | Cs748 Firmware | <= lhs60.cm4.p683 |
| Lexmark | Cs796 Firmware | < lhs60.hc.p683 |
| Lexmark | Cx410 Firmware | < lw71.gm4.p216 |
| Lexmark | Cx510 Firmware | < lw71.gm7.p216 |
| Lexmark | M3150 Firmware | < lw71.pr4.p216 |
| Lexmark | M5155 Firmware | < lw71.dn4.p216 |
| Lexmark | M5163 Firmware | < lw71.dn4.p216 |
| Lexmark | M5170 Firmware | < lw71.dn7.p216 |
| Lexmark | Ms610de Firmware | < lw71.pr4.p216 |
| Lexmark | Ms610dte Firmware | < lw71.pr4.p216 |
| Lexmark | Ms810de Firmware | < lw71.dn4.p216 |
| Lexmark | Ms812de Firmware | < lw71.dn7.p216 |
| Lexmark | Ms91x Firmware | < lw71.sa.p216 |
| Lexmark | Mx410 Firmware | < lw71.sb4.p216 |
| Lexmark | Mx510 Firmware | < lw71.sb4.p216 |
| Lexmark | Mx511 Firmware | < lw71.sb4.p216 |
| Lexmark | Mx610 Firmware | < lw71.sb7.p216 |
| Lexmark | Mx611 Firmware | < lw71.sb7.p216 |
| Lexmark | Mx6500e Firmware | <= lw71.jd.p216 |
| Lexmark | Mx71x Firmware | < lw71.tu.p216 |
| Lexmark | Mx81x Firmware | < lw71.tu.p216 |
| Lexmark | Mx91x Firmware | < lw71.mg.p216 |
| Lexmark | Sm91x Firmware | < lw71.mg.p216 |
| Lexmark | X46x Firmware | < lr.bs.p810 |
| Lexmark | X548 Firmware | < lhs60.vk.p683 |
| Lexmark | X65x Firmware | < lr.mn.p810 |
| Lexmark | X73x Firmware | < lr.fl.p810 |
| Lexmark | X74x Firmware | < lhs60.ny.p683 |
| Lexmark | X792 Firmware | < lhs60.mr.p683 |
| Lexmark | X86x Firmware | < lr.sp.p810 |
| Lexmark | X925 Firmware | < lhs60.hk.p683 |
| Lexmark | X95x Firmware | < lhs60.tq.p683 |
| Lexmark | Xc2132 Firmware | < lw71.gm7.p216 |
| Lexmark | Xm1145 Firmware | < lw71.sb4.p216 |
| Lexmark | Xm3150 Firmware | < lw71.sb7.p216 |
| Lexmark | Xm51xx Firmware | < lw71.tu.p216 |
| Lexmark | Xm71xx Firmware | < lw71.tu.p216 |
| Lexmark | Xs478 Firmware | < lhs60.ny.p683 |
| Lexmark | Xs548 Firmware | < lhs60.vk.p683 |
| Lexmark | Xs79x Firmware | < lhs60.mr.p683 |
| Lexmark | Xs925 Firmware | < lhs60.hk.p683 |
| Lexmark | Xs95x Firmware | < lhs60.tq.p683 |
References
- http://support.lexmark.com/alertsVendor Advisory
- http://support.lexmark.com/alertsVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18894?
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
How severe is CVE-2018-18894?
CVE-2018-18894 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.65% probability of exploitation in the next 30 days.
How do I fix CVE-2018-18894?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2018-18894?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
