CVE-2023-40239
Last modified
CVE-2023-40239 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lexmark | C2132 Firmware | <= lw80.vy4.p245 |
| Lexmark | Cs310 Firmware | <= lw80.vyl.p245 |
| Lexmark | Cs317 Firmware | <= lw80.vyl.p245 |
| Lexmark | Cs410 Firmware | <= lw80.vy2.p245 |
| Lexmark | Cs417 Firmware | <= lw80.vy2.p245 |
| Lexmark | Cs510 Firmware | <= lw80.vy4.p245 |
| Lexmark | Cs517 Firmware | <= lw80.vy4.p245 |
| Lexmark | Cx310 Firmware | <= lw80.gm2.p245 |
| Lexmark | Cx317 Firmware | <= lw80.gm2.p245 |
| Lexmark | Cx410 Firmware | <= lw80.gm4.p245 |
| Lexmark | Cx417 Firmware | <= lw80.gm4.p245 |
| Lexmark | Cx510 Firmware | <= lw80.gm7.p245 |
| Lexmark | Cx517 Firmware | <= lw80.gm7.p245 |
| Lexmark | M1140\+ Firmware | <= lw80.pr2.p245 |
| Lexmark | M1140 Firmware | <= lw80.prl.p245 |
| Lexmark | M1145 Firmware | <= lw80.pr2.p245 |
| Lexmark | M3150de Firmware | <= lw80.pr4.p245 |
| Lexmark | M3150dn Firmware | <= lw80.pr2.p245 |
| Lexmark | M5155 Firmware | <= lw80.dn4.p245 |
| Lexmark | M5163de Firmware | <= lw80.dn4.p245 |
| Lexmark | M5163dn Firmware | <= lw80.dn2.p245 |
| Lexmark | M5170 Firmware | <= lw80.dn7.p245 |
| Lexmark | Ms310 Firmware | <= lw80.prl.p245 |
| Lexmark | Ms312 Firmware | <= lw80.prl.p245 |
| Lexmark | Ms315 Firmware | <= lw80.tl2.p245 |
| Lexmark | Ms317 Firmware | <= lw80.prl.p245 |
| Lexmark | Ms410 Firmware | <= lw80.prl.p245 |
| Lexmark | Ms415 Firmware | <= lw80.tl2.p245 |
| Lexmark | Ms417 Firmware | <= lw80.tl2.p245 |
| Lexmark | Ms510 Firmware | <= lw80.pr2.p245 |
| Lexmark | Ms517 Firmware | <= lw80.pr2.p245 |
| Lexmark | Ms610de Firmware | <= lw80.pr4.p245 |
| Lexmark | Ms610dn Firmware | <= lw80.pr2.p245 |
| Lexmark | Ms617 Firmware | <= lw80.pr2.p245 |
| Lexmark | Ms710 Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms711 Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms810de Firmware | <= lw80.dn4.p245 |
| Lexmark | Ms810dn Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms811 Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms812de Firmware | <= lw80.dn7.p245 |
| Lexmark | Ms812dn Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms817 Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms818 Firmware | <= lw80.dn2.p245 |
| Lexmark | Ms911 Firmware | <= lw80.sa.p245 |
| Lexmark | Mx310 Firmware | <= lw80.sb2.p245 |
| Lexmark | Mx317 Firmware | <= lw80.sb2.p245 |
| Lexmark | Mx410 Firmware | <= lw80.sb4.p245 |
| Lexmark | Mx417 Firmware | <= lw80.sb4.p245 |
| Lexmark | Mx510 Firmware | <= lw80.sb4.p245 |
| Lexmark | Mx511 Firmware | <= lw80.sb4.p245 |
Showing 50 of 82 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40239?
How severe is CVE-2023-40239?
How do I fix CVE-2023-40239?
Are you affected by CVE-2023-40239?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
