CVE-2010-0618
Estado: ModificadaMedia (5)—
The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows remote attackers to cause a denial of service (TCP outage) by making many passive FTP connections and then aborting these connections.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.44%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/39056
- http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US
- http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=11&Itemid=11
- http://www.securityfocus.com/archive/1/510285/100/0/threaded
- http://www.securityfocus.com/bid/38906
- http://secunia.com/advisories/39056
- http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US
- http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=11&Itemid=11
- http://www.securityfocus.com/archive/1/510285/100/0/threaded
- http://www.securityfocus.com/bid/38906
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-0618",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-03-24T22:45:15.937",
"references": [
{
"url": "http://secunia.com/advisories/39056",
"source": "cve@mitre.org"
},
{
"url": "http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=11&Itemid=11",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/510285/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/38906",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/39056",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=11&Itemid=11",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/510285/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/38906",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows remote attackers to cause a denial of service (TCP outage) by making many passive FTP connections and then aborting these connections."
},
{
"lang": "es",
"value": "La característica flood-protection en la base de los componentes IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, y Printcryption DLE en determinadas impresoras multifunción o láser de la marca Lexmark, permite a atacantes remotos provocar una denegación de servicio (indisponibilidad de TCP) a través de varias conexiones FTP pasivas y posteriormente cancelando las conexiones."
}
],
"lastModified": "2026-06-16T23:16:30.863",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lexmark:z2420:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D331850-E67A-4183-9598-0A54CCD9CB77"
}
],
"operator": "OR"
}
]
}
],
"evaluatorImpact": "Per: http://support.lexmark.com/index?page=content&id=TE85&locale=EN&userlocale=EN_US#Printcryption\r\n\r\n'Details\r\n\r\nLexmark products have connection flood protection mechanisms that limit the number of simultaneous network connections that can be made to the device on most TCP service ports.\r\n\r\n(21/FTP 79/Finger, 515/LPD, 631/IPP, 5001, 9100-9104, 9200, 9300, 9400, 9500-9501 & 9600)\r\n\r\nThe FTP service exception handler does not properly maintain the state of the flood protection when passive FTP connections are aborted. Once a sufficient number of passive FTP connections have timed out (typically 15), the flood protection is enabled and is never reset.\r\n\r\nThe flood protection can be reset by resetting the network adapter, or by power cycling the device.\r\n\r\nThe firmware update that resolves this vulnerability automatically resets the flood protection after the “Network Job Timeout” has expired or 90 seconds if the “Network Job Timeout” is disabled.'",
"sourceIdentifier": "cve@mitre.org"
}