Lexmark International manufactures a broad line of multifunction printers and imaging devices deployed across enterprise and mid-market environments, creating a large attack surface spanning numerous product families and firmware revisions. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the combination of embedded complexity, network accessibility, and deep trust these devices hold in organizational infrastructure. The recurring exposure centers on printer and copier products such as the CX310, X46x, M5163DN, MS811, and MS817 series and clusters through weakness classes including improper input validation, buffer-boundary violations, path-traversal flaws, cross-site scripting, and sensitive-information disclosure—patterns endemic to embedded web interfaces and document-processing firmware. Defenders should treat Lexmark device firmware as a critical-patching category, inventory internet-reachable or network-accessible units, and apply administrative controls to isolate management interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lexmark International Inc. over time
Of all the CVEs published by Lexmark International Inc. as a CNA, 9.5% affect products that Lexmark International Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Lexmark International Inc., 2.9% are self-published by Lexmark International Inc. as a CNA.
Signals from CVEs in this vendor scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8741CRITICAL Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecif | Jan 27, 2020 | 9.8 | 82 | NO | YES |
CVE-2023-26067HIGH Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | Apr 10, 2023 | 8.1 | 59 | NO | YES |
CVE-2023-26068CRITICAL Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). | Apr 10, 2023 | 9.8 | 47 | NO | YES |
CVE-2019-16758HIGH In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local fi | Nov 21, 2019 | 7.5 | 42 | NO | YES |
CVE-2023-23560CRITICAL In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation. | Jan 23, 2023 | 9.8 | 39 | NO | NO |
CVE-2023-22960HIGH Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. | Jan 23, 2023 | 7.5 | 38 | NO | NO |
CVE-2021-35449HIGH The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege | Jul 19, 2021 | 7.8 | 35 | NO | YES |
CVE-2021-44735CRITICAL Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. | Jan 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-44734CRITICAL Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. | Jan 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-44738CRITICAL Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. | Jan 20, 2022 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (68 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lexmark International Inc..
Media articles that mention a CVE ID that affects a product developed by Lexmark International Inc. — matched by CVE ID, not by vendor name.