Cross-Site Scripting Vulnerability in Lexmark Printers
CVE-2020-10094

5.4MEDIUM

Key Information:

Vendor

Lexmark

Vendor
CVE Published:
28 April 2020

What is CVE-2020-10094?

This issues originates from improper input validation within Lexmark printers, enabling attackers to inject malicious scripts into web pages viewed by users. This flaw affects numerous models and configurations of Lexmark printers, leading to potential unauthorized actions on behalf of the user or exposure to malicious content when accessing the web interface. Users are encouraged to update their devices to the latest firmware to mitigate this security risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-10094 : Cross-Site Scripting Vulnerability in Lexmark Printers