CVE-2013-6033
Summary
| CVE | CVE-2013-6033 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-04 05:39:00 UTC |
| Updated | 2014-02-04 15:37:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allow remote authenticated users to inject arbitrary web script or HTML by using (1) SNMP or (2) the Embedded Web Server (EWS) to set the (a) Contact or (b) Location field. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lexmark | C52x | All | All | All | All |
| Hardware | Lexmark | C53x | All | All | All | All |
| Hardware | Lexmark | C920 | All | All | All | All |
| Hardware | Lexmark | C935dn | All | All | All | All |
| Hardware | Lexmark | E250 | All | All | All | All |
| Hardware | Lexmark | E350 | All | All | All | All |
| Hardware | Lexmark | E450 | All | All | All | All |
| Hardware | Lexmark | T64x | All | All | All | All |
| Hardware | Lexmark | W840 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Lexmark Security Advisory: | CONFIRM | support.lexmark.com | Vendor Advisory |
| Vulnerability Note VU#108062 - Lexmark laser printers contain multiple vulnerabilities | CERT-VN | www.kb.cert.org | US Government Resource |
| Lexmark Laser Printers CVE-2013-6033 HTML Injection Vulnerability | BID | www.securityfocus.com | |
| 102752 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.