CVE-2019-19772
Last modified
CVE-2019-19772 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lexmark | Cs31x Firmware | <= lw74.vyl.p267 |
| Lexmark | Cs41x Firmware | <= lw74.vy2.p267 |
| Lexmark | Cs51x Firmware | <= lw74.vy4.p267 |
| Lexmark | Cx310 Firmware | <= lw74.gm2.p267 |
| Lexmark | Cx410 Firmware | <= lw74.gm4.p267 |
| Lexmark | Xc2130 Firmware | <= lw74.gm4.p267 |
| Lexmark | Cx510 Firmware | <= lw74.gm7.p267 |
| Lexmark | Xc2132 Firmware | <= lw74.gm7.p267 |
| Lexmark | Ms310 Firmware | <= lw74.prl.p267 |
| Lexmark | Ms312 Firmware | <= lw74.prl.p267 |
| Lexmark | Ms317 Firmware | <= lw74.prl.p267 |
| Lexmark | Ms410 Firmware | <= lw74.prl.p267 |
| Lexmark | M1140 Firmware | <= lw74.prl.p267 |
| Lexmark | Ms315 Firmware | <= lw74.tl2.p267 |
| Lexmark | Ms415 Firmware | <= lw74.tl2.p267 |
| Lexmark | Ms417 Firmware | <= lw74.tl2.p267 |
| Lexmark | Ms51x Firmware | <= lw74.pr2.p267 |
| Lexmark | Ms610dn Firmware | <= lw74.pr2.p267 |
| Lexmark | Ms617 Firmware | <= lw74.pr2.p267 |
| Lexmark | M1145 Firmware | <= lw74.pr2.p267 |
| Lexmark | M3150dn Firmware | <= lw74.pr2.p267 |
| Lexmark | Ms610de Firmware | <= lw74.pr4.p267 |
| Lexmark | M3150 Firmware | <= lw74.pr4.p267 |
| Lexmark | Ms71x Firmware | <= lw74.dn2.p267 |
| Lexmark | M5163dn Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms810 Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms811 Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms812 Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms817 Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms818 Firmware | <= lw74.dn2.p267 |
| Lexmark | Ms810de Firmware | <= lw74.dn4.p267 |
| Lexmark | M5155 Firmware | <= lw74.dn4.p267 |
| Lexmark | M5163 Firmware | <= lw74.dn4.p267 |
| Lexmark | Ms812de Firmware | <= lw74.dn7.p267 |
| Lexmark | M5170 Firmware | <= lw74.dn7.p267 |
| Lexmark | Ms91x Firmware | <= lw74.sa.p267 |
| Lexmark | Mx31x Firmware | <= lw74.sb2.p267 |
| Lexmark | Xm1135 Firmware | <= lw74.sb2.p267 |
| Lexmark | Mx410 Firmware | <= lw74.sb4.p267 |
| Lexmark | Mx510 Firmware | <= lw74.sb4.p267 |
| Lexmark | Mx511 Firmware | <= lw74.sb4.p267 |
| Lexmark | Xm1140 Firmware | <= lw74.sb4.p267 |
| Lexmark | Xm1145 Firmware | <= lw74.sb4.p267 |
| Lexmark | Mx610 Firmware | <= lw74.sb7.p267 |
| Lexmark | Mx611 Firmware | <= lw74.sb7.p267 |
| Lexmark | Xm3150 Firmware | <= lw74.sb7.p267 |
| Lexmark | Mx71x Firmware | <= lw74.tu.p267 |
| Lexmark | Mx81x Firmware | <= lw74.tu.p267 |
| Lexmark | Xm51xx Firmware | <= lw74.tu.p267 |
| Lexmark | Xm71xx Firmware | <= lw74.tu.p267 |
Showing 50 of 80 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19772?
How severe is CVE-2019-19772?
How do I fix CVE-2019-19772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19767The Linux kernel before 5.4.2 mishandles ext4_expand_extra_i…5.5
- CVE-2019-19768In the Linux kernel 5.4.0-rc2, there is a use-after-free (re…7.5
- CVE-2019-19769In the Linux kernel 5.3.10, there is a use-after-free (read)…6.7
- CVE-2019-1977A vulnerability within the Endpoint Learning feature of Cisc…6.8
- CVE-2019-19770In the Linux kernel 4.19.83, there is a use-after-free (read…8.2
- CVE-2019-19771The lodahs package 0.0.1 for Node.js is a Trojan horse, and …8.8
- CVE-2019-19773Various Lexmark products have stored XSS in the embedded web…5.4
- CVE-2019-19774An issue was discovered in Zoho ManageEngine EventLog Analyz…8.8
- CVE-2019-19775The image thumbnailing handler in Zulip Server versions 1.9.…6.1
- CVE-2019-19777stb_image.h (aka the stb image loader) 2.23, as used in libs…8.8
- CVE-2019-19778An issue was discovered in libsixel 1.8.2. There is a heap-b…8.8
- CVE-2019-1978A vulnerability in the stream reassembly component of Cisco …5.8
Are you affected by CVE-2019-19772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
