ZeroHour

CVE-2023-40239

CVSS 3.1
7.5 high
EPSS
<1%p44
Published
()
Modified
Description

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

Vendors
lexmark
Products
c2132 firmware, cs310 firmware, cs317 firmware, cs410 firmware, cs417 firmware, cs510 firmware, cs517 firmware, cx310 firmware, cx317 firmware, cx410 firmware, cx417 firmware, cx510 firmware
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.