Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
Conclusion & alert: CVE-2011-4538 is rated Moderate Risk (40.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.87%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.23% | 0.87% | +0.64% |
| 2 | 2025-03-30 | 0.28% | 0.23% | -0.04% |
| 3 | 2025-03-29 | — | 0.28% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lexmark | x860_firmware | <= lp.sp.p108 | cpe:2.3:o:lexmark:x860_firmware:*:*:*:*:*:*:*:* |
| lexmark | x862_firmware | <= lp.sp.p108 | cpe:2.3:o:lexmark:x862_firmware:*:*:*:*:*:*:*:* |
| lexmark | x864_firmware | <= lp.sp.p108 | cpe:2.3:o:lexmark:x864_firmware:*:*:*:*:*:*:*:* |
| lexmark | x734_firmware | <= lr.fl.p224c | cpe:2.3:o:lexmark:x734_firmware:*:*:*:*:*:*:*:* |
| lexmark | x736_firmware | <= lr.fl.p224c | cpe:2.3:o:lexmark:x736_firmware:*:*:*:*:*:*:*:* |
| lexmark | x738_firmware | <= lr.fl.p224c | cpe:2.3:o:lexmark:x738_firmware:*:*:*:*:*:*:*:* |
| lexmark | x651_firmware | <= lr.mn.p224a | cpe:2.3:o:lexmark:x651_firmware:*:*:*:*:*:*:*:* |
| lexmark | x652_firmware | <= lr.mn.p224a | cpe:2.3:o:lexmark:x652_firmware:*:*:*:*:*:*:*:* |
| lexmark | x654_firmware | <= lr.mn.p224a | cpe:2.3:o:lexmark:x654_firmware:*:*:*:*:*:*:*:* |
| lexmark | x656_firmware | <= lr.mn.p224a | cpe:2.3:o:lexmark:x656_firmware:*:*:*:*:*:*:*:* |
| lexmark | x658_firmware | <= lr.mn.p224a | cpe:2.3:o:lexmark:x658_firmware:*:*:*:*:*:*:*:* |
| lexmark | x543_firmware | <= ll.el.p511 | cpe:2.3:o:lexmark:x543_firmware:*:*:*:*:*:*:*:* |
| lexmark | x544_firmware | <= ll.el.p511 | cpe:2.3:o:lexmark:x544_firmware:*:*:*:*:*:*:*:* |
| lexmark | x546_firmware | <= ll.el.p511 | cpe:2.3:o:lexmark:x546_firmware:*:*:*:*:*:*:*:* |
| lexmark | x463_firmware | <= lr.bs.p224a | cpe:2.3:o:lexmark:x463_firmware:*:*:*:*:*:*:*:* |
| lexmark | x464_firmware | <= lr.bs.p224a | cpe:2.3:o:lexmark:x464_firmware:*:*:*:*:*:*:*:* |
| lexmark | x466_firmware | <= lr.bs.p224a | cpe:2.3:o:lexmark:x466_firmware:*:*:*:*:*:*:*:* |
| lexmark | x363_firmware | <= ll.bz.p511 | cpe:2.3:o:lexmark:x363_firmware:*:*:*:*:*:*:*:* |
| lexmark | x364_firmware | <= ll.bz.p511 | cpe:2.3:o:lexmark:x364_firmware:*:*:*:*:*:*:*:* |
| lexmark | w850_firmware | <= lp.jb.p108 | cpe:2.3:o:lexmark:w850_firmware:*:*:*:*:*:*:*:* |
| lexmark | t650_firmware | <= lr.jp.p224a | cpe:2.3:o:lexmark:t650_firmware:*:*:*:*:*:*:*:* |
| lexmark | t652_firmware | <= lr.jp.p224a | cpe:2.3:o:lexmark:t652_firmware:*:*:*:*:*:*:*:* |
| lexmark | t654_firmware | <= lr.jp.p224a | cpe:2.3:o:lexmark:t654_firmware:*:*:*:*:*:*:*:* |
| lexmark | e460_firmware | <= lr.lbh.p224a | cpe:2.3:o:lexmark:e460_firmware:*:*:*:*:*:*:*:* |
| lexmark | e462_firmware | <= lr.lbh.p224a | cpe:2.3:o:lexmark:e462_firmware:*:*:*:*:*:*:*:* |
| lexmark | e360_firmware | <= ll.lbm.p511 | cpe:2.3:o:lexmark:e360_firmware:*:*:*:*:*:*:*:* |
| lexmark | e260_firmware | <= ll.lbl.p511 | cpe:2.3:o:lexmark:e260_firmware:*:*:*:*:*:*:*:* |
| lexmark | c734_firmware | <= lr.sk.p224a | cpe:2.3:o:lexmark:c734_firmware:*:*:*:*:*:*:*:* |
| lexmark | c736_firmware | <= lr.sk.p224a | cpe:2.3:o:lexmark:c736_firmware:*:*:*:*:*:*:*:* |
| lexmark | c546_firmware | <= lu.as.p511 | cpe:2.3:o:lexmark:c546_firmware:*:*:*:*:*:*:*:* |
| lexmark | c540_firmware | <= ll.as.p511 | cpe:2.3:o:lexmark:c540_firmware:*:*:*:*:*:*:*:* |
| lexmark | c543_firmware | <= ll.as.p511 | cpe:2.3:o:lexmark:c543_firmware:*:*:*:*:*:*:*:* |
| lexmark | c544_firmware | <= ll.as.p511 | cpe:2.3:o:lexmark:c544_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://contentdelivery.lexmark.com/webcontent/CVE-2011-4538.pdf | Third Party Advisory |