CVE-2020-10093

MEDIUMCVSS 5.4/10EPSS 0.65%

Last modified

CVE-2020-10093 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.

Description

A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.

Metrics

CVSS 3.1
5.4/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
0.65%

46.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LexmarkCs31x Firmware<= lw74.vyl.p272
LexmarkCs41x Firmware<= lw74.vy2.p272
LexmarkCs51x Firmware<= lw74.vy4.p272
LexmarkCx310 Firmware<= lw74.gm2.p272
LexmarkCx410 Firmware<= lw74.gm4.p272
LexmarkXc2130 Firmware<= lw74.gm4.p272
LexmarkCx510 Firmware<= lw74.gm7.p272
LexmarkXc2132 Firmware<= lw74.gm7.p272
LexmarkMs310 Firmware<= lw74.prl.p272
LexmarkMs312 Firmware<= lw74.prl.p272
LexmarkMs317 Firmware<= lw74.prl.p272
LexmarkMs410 Firmware<= lw74.prl.p272
LexmarkM1140 Firmware<= lw74.prl.p272
LexmarkMs315 Firmware<= lw74.tl2.p272
LexmarkMs415 Firmware<= lw74.tl2.p272
LexmarkMs417 Firmware<= lw74.tl2.p272
LexmarkMs51x Firmware<= lw74.pr2.p272
LexmarkMs610dn Firmware<= lw74.pr2.p272
LexmarkMs617 Firmware<= lw74.pr2.p272
LexmarkM1145 Firmware<= lw74.pr2.p272
LexmarkM3150dn Firmware<= lw74.pr2.p272
LexmarkMs610de Firmware<= lw74.pr4.p272
LexmarkM3150 Firmware<= lw74.pr4.p272
LexmarkMs71x Firmware<= lw74.dn2.p272
LexmarkM5163dn Firmware<= lw74.dn2.p272
LexmarkMs810 Firmware<= lw74.dn2.p272
LexmarkMs811 Firmware<= lw74.dn2.p272
LexmarkMs812 Firmware<= lw74.dn2.p272
LexmarkMs817 Firmware<= lw74.dn2.p272
LexmarkMs818 Firmware<= lw74.dn2.p272
LexmarkMs810de Firmware<= lw74.dn4.p272
LexmarkM5155 Firmware<= lw74.dn4.p272
LexmarkM5163 Firmware<= lw74.dn4.p272
LexmarkMs812de Firmware<= lw74.dn7.p272
LexmarkM5170 Firmware<= lw74.dn7.p272
LexmarkMs91x Firmware<= lw74.sa.p272
LexmarkMx31x Firmware<= lw74.sb2.p272
LexmarkXm1135 Firmware<= lw74.sb2.p272
LexmarkMx410 Firmware<= lw74.sb4.p272
LexmarkMx510 Firmware<= lw74.sb4.p272
LexmarkMx511 Firmware<= lw74.sb4.p272
LexmarkXm1140 Firmware<= lw74.sb4.p272
LexmarkXm1145 Firmware<= lw74.sb4.p272
LexmarkMx610 Firmware<= lw74.sb7.p272
LexmarkMx611 Firmware<= lw74.sb7.p272
LexmarkXm3150 Firmware<= lw74.sb7.p272
LexmarkMx71x Firmware<= lw74.tu.p272
LexmarkMx81x Firmware<= lw74.tu.p272
LexmarkXm51xx Firmware<= lw74.tu.p272
LexmarkXm71xx Firmware<= lw74.tu.p272

Showing 50 of 80 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-10093?
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
How severe is CVE-2020-10093?
CVE-2020-10093 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2020-10093?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-10093?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST