Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Conclusion & alert: CVE-2018-18894 is rated Moderate Risk (46.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.71% | 0.27% | -0.44% |
| 2 | 2025-03-29 | 0.28% | 0.71% | +0.43% |
| 3 | 2025-03-17 | — | 0.28% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lexmark | 6500e_firmware | < lhs60.jr.p683 | cpe:2.3:o:lexmark:6500e_firmware:*:*:*:*:*:*:*:* |
| lexmark | c748_firmware | < lhs60.cm4.p683 | cpe:2.3:o:lexmark:c748_firmware:*:*:*:*:*:*:*:* |
| lexmark | c79x_firmware | < lhs60.hc.p683 | cpe:2.3:o:lexmark:c79x_firmware:*:*:*:*:*:*:*:* |
| lexmark | c925_firmware | < lhs60.hv.p683 | cpe:2.3:o:lexmark:c925_firmware:*:*:*:*:*:*:*:* |
| lexmark | c95x_firmware | < lhs60.tp.p683 | cpe:2.3:o:lexmark:c95x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs41x_firmware | < lw71.vy2.p216 | cpe:2.3:o:lexmark:cs41x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs51x_firmware | < lw71.vy4.p216 | cpe:2.3:o:lexmark:cs51x_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs748_firmware | <= lhs60.cm4.p683 | cpe:2.3:o:lexmark:cs748_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs796_firmware | < lhs60.hc.p683 | cpe:2.3:o:lexmark:cs796_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx410_firmware | < lw71.gm4.p216 | cpe:2.3:o:lexmark:cx410_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx510_firmware | < lw71.gm7.p216 | cpe:2.3:o:lexmark:cx510_firmware:*:*:*:*:*:*:*:* |
| lexmark | m3150_firmware | < lw71.pr4.p216 | cpe:2.3:o:lexmark:m3150_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5155_firmware | < lw71.dn4.p216 | cpe:2.3:o:lexmark:m5155_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5163_firmware | < lw71.dn4.p216 | cpe:2.3:o:lexmark:m5163_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5170_firmware | < lw71.dn7.p216 | cpe:2.3:o:lexmark:m5170_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms610de_firmware | < lw71.pr4.p216 | cpe:2.3:o:lexmark:ms610de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms610dte_firmware | < lw71.pr4.p216 | cpe:2.3:o:lexmark:ms610dte_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms810de_firmware | < lw71.dn4.p216 | cpe:2.3:o:lexmark:ms810de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms812de_firmware | < lw71.dn7.p216 | cpe:2.3:o:lexmark:ms812de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms91x_firmware | < lw71.sa.p216 | cpe:2.3:o:lexmark:ms91x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx410_firmware | < lw71.sb4.p216 | cpe:2.3:o:lexmark:mx410_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx510_firmware | < lw71.sb4.p216 | cpe:2.3:o:lexmark:mx510_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx511_firmware | < lw71.sb4.p216 | cpe:2.3:o:lexmark:mx511_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx610_firmware | < lw71.sb7.p216 | cpe:2.3:o:lexmark:mx610_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx611_firmware | < lw71.sb7.p216 | cpe:2.3:o:lexmark:mx611_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx6500e_firmware | <= lw71.jd.p216 | cpe:2.3:o:lexmark:mx6500e_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx71x_firmware | < lw71.tu.p216 | cpe:2.3:o:lexmark:mx71x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx81x_firmware | < lw71.tu.p216 | cpe:2.3:o:lexmark:mx81x_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx91x_firmware | < lw71.mg.p216 | cpe:2.3:o:lexmark:mx91x_firmware:*:*:*:*:*:*:*:* |
| lexmark | sm91x_firmware | < lw71.mg.p216 | cpe:2.3:o:lexmark:sm91x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x46x_firmware | < lr.bs.p810 | cpe:2.3:o:lexmark:x46x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x548_firmware | < lhs60.vk.p683 | cpe:2.3:o:lexmark:x548_firmware:*:*:*:*:*:*:*:* |
| lexmark | x65x_firmware | < lr.mn.p810 | cpe:2.3:o:lexmark:x65x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x73x_firmware | < lr.fl.p810 | cpe:2.3:o:lexmark:x73x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x74x_firmware | < lhs60.ny.p683 | cpe:2.3:o:lexmark:x74x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x792_firmware | < lhs60.mr.p683 | cpe:2.3:o:lexmark:x792_firmware:*:*:*:*:*:*:*:* |
| lexmark | x86x_firmware | < lr.sp.p810 | cpe:2.3:o:lexmark:x86x_firmware:*:*:*:*:*:*:*:* |
| lexmark | x925_firmware | < lhs60.hk.p683 | cpe:2.3:o:lexmark:x925_firmware:*:*:*:*:*:*:*:* |
| lexmark | x95x_firmware | < lhs60.tq.p683 | cpe:2.3:o:lexmark:x95x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc2132_firmware | < lw71.gm7.p216 | cpe:2.3:o:lexmark:xc2132_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm1145_firmware | < lw71.sb4.p216 | cpe:2.3:o:lexmark:xm1145_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm3150_firmware | < lw71.sb7.p216 | cpe:2.3:o:lexmark:xm3150_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm51xx_firmware | < lw71.tu.p216 | cpe:2.3:o:lexmark:xm51xx_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm71xx_firmware | < lw71.tu.p216 | cpe:2.3:o:lexmark:xm71xx_firmware:*:*:*:*:*:*:*:* |
| lexmark | xs478_firmware | < lhs60.ny.p683 | cpe:2.3:o:lexmark:xs478_firmware:*:*:*:*:*:*:*:* |
| lexmark | xs548_firmware | < lhs60.vk.p683 | cpe:2.3:o:lexmark:xs548_firmware:*:*:*:*:*:*:*:* |
| lexmark | xs79x_firmware | < lhs60.mr.p683 | cpe:2.3:o:lexmark:xs79x_firmware:*:*:*:*:*:*:*:* |
| lexmark | xs925_firmware | < lhs60.hk.p683 | cpe:2.3:o:lexmark:xs925_firmware:*:*:*:*:*:*:*:* |
| lexmark | xs95x_firmware | < lhs60.tq.p683 | cpe:2.3:o:lexmark:xs95x_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://support.lexmark.com/alerts | Vendor Advisory |
| http://support.lexmark.com/index?page=content&id=TE906&locale=EN&userlocale=EN_US | Vendor Advisory |