CVE-2014-8741

CRITICAL

Lexmark MarkVision Enterprise <2.1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/35776
metasploit WORKING POC EXCELLENT
by Andrea Micalizzi, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/lexmark_markvision_gfd_upload.rb

Scores

CVSS v3 9.8
EPSS 0.7035
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
lexmark/markvision_enterprise < 2.1
Published Jan 27, 2020
Tracked Since Feb 18, 2026