← Vulnerability feed

Vulnerability record · CVE-2019-10059 · published 28 August 2019

CVE-2019-10059: Lexmark cs31x firmware vulnerability

Lexmark · Cs31x Firmware

The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.

5.3 CVSS 3.0 Medium EPSS 0.87% · top 42.8% CWE-254 · CWE-254
5.3CVSS 3.0 base score, v2 5.0
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
71Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

71 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10059 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9930Lexmark cs31x firmware integer overflow vulnerabilityVarious Lexmark products have an Integer Overflow.EPSS 1.5%9.8CVE-2019-9932Lexmark cs31x firmware memory buffer overflow vulnerabilityVarious Lexmark products have a Buffer Overflow (issue 2 of 3).EPSS 1.5%9.8CVE-2019-9933Lexmark cs31x firmware memory buffer overflow vulnerabilityVarious Lexmark products have a Buffer Overflow (issue 3 of 3).EPSS 1.5%9.1CVE-2019-10058Lexmark cs31x firmware vulnerabilityVarious Lexmark products have Incorrect Access Control.EPSS 1.1%7.5CVE-2018-18894Lexmark 6500e firmware path traversal vulnerabilityCertain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.EPSS 1.7%7.5CVE-2011-3269Lexmark x950 firmware information exposure vulnerabilityLexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…EPSS 1.1%7.5CVE-2019-9931Lexmark cs31x firmware vulnerabilityVarious Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.EPSS 1.1%5.4CVE-2020-10094Lexmark cs31x firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 befor…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2019-10059), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.