Lexmark Xm7270 Firmware vulnerabilities
4 known vulnerabilities affecting lexmark/xm7270_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2023-40239HIGHCVSS 7.5≤ lw80.tu.p2452023-09-01
CVE-2023-40239 [HIGH] CWE-611 CVE-2023-40239: Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
nvd
CVE-2021-44734CRITICALCVSS 9.8fixed in lw80.tu.p2102022-01-20
CVE-2021-44734 [CRITICAL] CWE-94 CVE-2021-44734: Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which ca
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
nvd
CVE-2021-44738CRITICALCVSS 9.8fixed in lw80.tu.p2102022-01-20
CVE-2021-44738 [CRITICAL] CWE-120 CVE-2021-44738: Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscrip
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
nvd
CVE-2021-44737HIGHCVSS 8.8fixed in lw80.tu.p2102022-01-20
CVE-2021-44737 [HIGH] CWE-22 CVE-2021-44737: PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
nvd