Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
Conclusion & alert: CVE-2018-15520 is rated Moderate Risk (62.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.19%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.54% | 1.19% | +0.64% |
| 2 | 2025-03-30 | 1.05% | 0.54% | -0.51% |
| 3 | 2025-03-29 | — | 1.05% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lexmark | cx82x_firmware | <= cxtpp.052.024 | cpe:2.3:o:lexmark:cx82x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx82x_firmware | >= cxtpp.052.200, <= cxtpp.052.204 | cpe:2.3:o:lexmark:cx82x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx860_firmware | <= cxtpp.052.024 | cpe:2.3:o:lexmark:cx860_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx860_firmware | >= cxtpp.052.200, <= cxtpp.052.204 | cpe:2.3:o:lexmark:cx860_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc6152_firmware | <= cxtpp.052.024 | cpe:2.3:o:lexmark:xc6152_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc6152_firmware | >= cxtpp.052.200, <= cxtpp.052.204 | cpe:2.3:o:lexmark:xc6152_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc8155_firmware | <= cxtpp.052.024 | cpe:2.3:o:lexmark:xc8155_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc8155_firmware | >= cxtpp.052.200, <= cxtpp.052.204 | cpe:2.3:o:lexmark:xc8155_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc8160_firmware | <= cxtpp.052.024 | cpe:2.3:o:lexmark:xc8160_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc8160_firmware | >= cxtpp.052.200, <= cxtpp.052.204 | cpe:2.3:o:lexmark:xc8160_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx72x_firmware | <= cxtat.052.024 | cpe:2.3:o:lexmark:cx72x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx72x_firmware | >= cxtat.052.200, <= cxtat.052.204 | cpe:2.3:o:lexmark:cx72x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc41x0_firmware | <= cxtat.052.024 | cpe:2.3:o:lexmark:xc41x0_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc41x0_firmware | >= cxtat.052.200, <= cxtat.052.204 | cpe:2.3:o:lexmark:xc41x0_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx92x_firmware | <= cxtmh.052.024 | cpe:2.3:o:lexmark:cx92x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx92x_firmware | >= cxtmh.052.200, <= cxtmh.052.204 | cpe:2.3:o:lexmark:cx92x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc92x5_firmware | <= cxtmh.052.024 | cpe:2.3:o:lexmark:xc92x5_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc92x5_firmware | >= cxtmh.052.200, <= cxtmh.052.204 | cpe:2.3:o:lexmark:xc92x5_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx321_firmware | <= mxngm.052.024 | cpe:2.3:o:lexmark:mx321_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx321_firmware | >= mxngm.052.200, <= mxngm.052.204 | cpe:2.3:o:lexmark:mx321_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2338_firmware | <= mxngm.052.024 | cpe:2.3:o:lexmark:mb2338_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2338_firmware | >= mxngm.052.200, <= mxngm.052.204 | cpe:2.3:o:lexmark:mb2338_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx42x_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mx42x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx42x_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mx42x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx52x_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mx52x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx52x_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mx52x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx622_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mx622_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx622_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mx622_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2442_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mb2442_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2442_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mb2442_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2546_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mb2546_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2546_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mb2546_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2650_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:mb2650_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2650_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:mb2650_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm124x_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:xm124x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm124x_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:xm124x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm3250_firmware | <= mxtgm.052.024 | cpe:2.3:o:lexmark:xm3250_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm3250_firmware | >= mxtgm.052.200, <= mxtgm.052.204 | cpe:2.3:o:lexmark:xm3250_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx72x_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:mx72x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx72x_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:mx72x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx82x_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:mx82x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx82x_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:mx82x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2770_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:mb2770_firmware:*:*:*:*:*:*:*:* |
| lexmark | mb2770_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:mb2770_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5370_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:xm5370_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5370_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:xm5370_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7355_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:xm7355_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7355_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:xm7355_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7370_firmware | <= mxtgw.052.024 | cpe:2.3:o:lexmark:xm7370_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7370_firmware | >= mxtgw.052.200, <= mxtgw.052.204 | cpe:2.3:o:lexmark:xm7370_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx421_firmware | <= cxnzj.052.024 | cpe:2.3:o:lexmark:cx421_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx421_firmware | >= cxnzj.052.200, <= cxnzj.052.204 | cpe:2.3:o:lexmark:cx421_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2325_firmware | <= cxnzj.052.024 | cpe:2.3:o:lexmark:mc2325_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2325_firmware | >= cxnzj.052.200, <= cxnzj.052.204 | cpe:2.3:o:lexmark:mc2325_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2425_firmware | <= cxnzj.052.024 | cpe:2.3:o:lexmark:mc2425_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2425_firmware | >= cxnzj.052.200, <= cxnzj.052.204 | cpe:2.3:o:lexmark:mc2425_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx522_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:cx522_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx522_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:cx522_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx62x_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:cx62x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx62x_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:cx62x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2535_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:mc2535_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2535_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:mc2535_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2640_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:mc2640_firmware:*:*:*:*:*:*:*:* |
| lexmark | mc2640_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:mc2640_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc2235_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:xc2235_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc2235_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:xc2235_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc4240_firmware | <= cxtzj.052.024 | cpe:2.3:o:lexmark:xc4240_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc4240_firmware | >= cxtzj.052.200, <= cxtzj.052.204 | cpe:2.3:o:lexmark:xc4240_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://support.lexmark.com/index?page=content&id=TE892 | Vendor Advisory |