cbcvebase.
CVE-2023-40239
published 2023-09-01

CVE-2023-40239: Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

Affected

82 ranges· showing 25
VendorProductVersion rangeFixed in
lexmarkc2132_firmware<= lw80.vy4.p245
lexmarkcs310_firmware<= lw80.vyl.p245
lexmarkcs317_firmware<= lw80.vyl.p245
lexmarkcs410_firmware<= lw80.vy2.p245
lexmarkcs417_firmware<= lw80.vy2.p245
lexmarkcs510_firmware<= lw80.vy4.p245
lexmarkcs517_firmware<= lw80.vy4.p245
lexmarkcx310_firmware<= lw80.gm2.p245
lexmarkcx317_firmware<= lw80.gm2.p245
lexmarkcx410_firmware<= lw80.gm4.p245
lexmarkcx417_firmware<= lw80.gm4.p245
lexmarkcx510_firmware<= lw80.gm7.p245
lexmarkcx517_firmware<= lw80.gm7.p245
lexmarkm1140_+_firmware<= lw80.pr2.p245
lexmarkm1140_firmware<= lw80.prl.p245
lexmarkm1145_firmware<= lw80.pr2.p245
lexmarkm3150de_firmware<= lw80.pr4.p245
lexmarkm3150dn_firmware<= lw80.pr2.p245
lexmarkm5155_firmware<= lw80.dn4.p245
lexmarkm5163de_firmware<= lw80.dn4.p245
lexmarkm5163dn_firmware<= lw80.dn2.p245
lexmarkm5170_firmware<= lw80.dn7.p245
lexmarkms310_firmware<= lw80.prl.p245
lexmarkms312_firmware<= lw80.prl.p245
lexmarkms315_firmware<= lw80.tl2.p245