Back to Database
Status published
High
CVE-2018-18894
Certain older Lexmark devices (C, M, X, and 6500e before...
Vulnerability Description
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18894
Credits & Attribution
No credits recorded in the NVD database.
References
More from lexmark
View All →CVE-2022-29850
Various Lexmark products through 2022-04-27 allow an attacker who has...
High
8.1
CVE-2022-24935
Lexmark products through 2022-02-10 have Incorrect Access Control....
High
7.5
CVE-2021-44738
Buffer overflow vulnerability has been identified in Lexmark devices through...
Critical
9.8
CVE-2021-44737
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that...
High
8.8
CVE-2021-44736
The initial admin account setup wizard on Lexmark devices allow...
Critical
9.8
Affected Vendor
lexmark
View all reports →Affected Software
6500e firmware, c748 firmware, c79x firmware, c925 firmware, c95x firmware, cs41x firmware, cs51x firmware, cs748 firmware, cs796 firmware, cx410 firmware, cx510 firmware, m3150 firmware, m5155 firmware, m5163 firmware, m5170 firmware, ms610de firmware, ms610dte firmware, ms810de firmware, ms812de firmware, ms91x firmware, mx410 firmware, mx510 firmware, mx511 firmware, mx610 firmware, mx611 firmware, mx6500e firmware, mx71x firmware, mx81x firmware, mx91x firmware, sm91x firmware, x46x firmware, x548 firmware, x65x firmware, x73x firmware, x74x firmware, x792 firmware, x86x firmware, x925 firmware, x95x firmware, xc2132 firmware, xm1145 firmware, xm3150 firmware, xm51xx firmware, xm71xx firmware, xs478 firmware, xs548 firmware, xs79x firmware, xs925 firmware, xs95x firmware
Vulnerable Versions:
0
Timeline
Official Publish:
March 10th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.