Vulnerabilities > Lexmark > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-01 CVE-2023-40239 XXE vulnerability in Lexmark products
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure.
network
low complexity
lexmark CWE-611
7.5
2023-04-10 CVE-2023-26067 Improper Input Validation vulnerability in Lexmark products
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
network
high complexity
lexmark CWE-20
8.1
2023-01-23 CVE-2023-22960 Improper Restriction of Excessive Authentication Attempts vulnerability in Lexmark products
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
network
low complexity
lexmark CWE-307
7.5
2022-08-26 CVE-2022-29850 Exposure of Resource to Wrong Sphere vulnerability in Lexmark products
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
network
high complexity
lexmark CWE-668
8.1
2022-04-28 CVE-2022-24935 Missing Authentication for Critical Function vulnerability in Lexmark Firmware
Lexmark products through 2022-02-10 have Incorrect Access Control.
network
low complexity
lexmark CWE-306
7.5
2022-01-20 CVE-2021-44737 Path Traversal vulnerability in Lexmark products
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
low complexity
lexmark CWE-22
8.3
2021-07-19 CVE-2021-35449 Incorrect Permission Assignment for Critical Resource vulnerability in Lexmark products
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability.
local
low complexity
lexmark CWE-732
7.2
2021-07-14 CVE-2021-35469 Unquoted Search Path or Element vulnerability in Lexmark products
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
local
low complexity
lexmark CWE-428
7.2
2020-03-09 CVE-2016-6918 Unrestricted Upload of File with Dangerous Type vulnerability in Lexmark Markvision Enterprise 2.1/2.3.0
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.
network
low complexity
lexmark CWE-434
7.5
2020-01-27 CVE-2014-8742 Path Traversal vulnerability in Lexmark Markvision Enterprise
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
lexmark CWE-22
7.8