Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

Project Subscriptions

Vendors Products
Lexmark Subscribe
C2132 Firmware Subscribe
Cs310 Firmware Subscribe
Cs317 Firmware Subscribe
Cs410 Firmware Subscribe
Cs417 Firmware Subscribe
Cs510 Firmware Subscribe
Cs517 Firmware Subscribe
Cx310 Firmware Subscribe
Cx317 Firmware Subscribe
Cx410 Firmware Subscribe
Cx417 Firmware Subscribe
Cx510 Firmware Subscribe
Cx517 Firmware Subscribe
M1140\+ Subscribe
M1140\+ Firmware Subscribe
M1140 Firmware Subscribe
M1145 Firmware Subscribe
M3150de Subscribe
M3150de Firmware Subscribe
M3150dn Subscribe
M3150dn Firmware Subscribe
M5155 Firmware Subscribe
M5163de Subscribe
M5163de Firmware Subscribe
M5163dn Subscribe
M5163dn Firmware Subscribe
M5170 Firmware Subscribe
Ms310 Firmware Subscribe
Ms312 Firmware Subscribe
Ms315 Firmware Subscribe
Ms317 Firmware Subscribe
Ms410 Firmware Subscribe
Ms415 Firmware Subscribe
Ms417 Firmware Subscribe
Ms510 Firmware Subscribe
Ms517 Firmware Subscribe
Ms610de Subscribe
Ms610de Firmware Subscribe
Ms610dn Subscribe
Ms610dn Firmware Subscribe
Ms617 Firmware Subscribe
Ms710 Firmware Subscribe
Ms711 Firmware Subscribe
Ms810de Subscribe
Ms810de Firmware Subscribe
Ms810dn Subscribe
Ms810dn Firmware Subscribe
Ms811 Firmware Subscribe
Ms812de Subscribe
Ms812de Firmware Subscribe
Ms812dn Subscribe
Ms812dn Firmware Subscribe
Ms817 Firmware Subscribe
Ms818 Firmware Subscribe
Ms911 Firmware Subscribe
Mx310 Firmware Subscribe
Mx317 Firmware Subscribe
Mx410 Firmware Subscribe
Mx417 Firmware Subscribe
Mx510 Firmware Subscribe
Mx511 Firmware Subscribe
Mx517 Firmware Subscribe
Mx610 Firmware Subscribe
Mx611 Firmware Subscribe
Mx617 Firmware Subscribe
Mx710 Firmware Subscribe
Mx711 Firmware Subscribe
Mx717 Firmware Subscribe
Mx718 Firmware Subscribe
Mx810 Firmware Subscribe
Mx811 Firmware Subscribe
Mx812 Firmware Subscribe
Mx910 Firmware Subscribe
Mx911 Firmware Subscribe
Mx912 Firmware Subscribe
Xc2130 Firmware Subscribe
Xc2132 Firmware Subscribe
Xm1135 Firmware Subscribe
Xm1140 Firmware Subscribe
Xm1145 Firmware Subscribe
Xm3150 Firmware Subscribe
Xm5163 Firmware Subscribe
Xm5170 Firmware Subscribe
Xm5263 Firmware Subscribe
Xm5270 Firmware Subscribe
Xm7155 Firmware Subscribe
Xm7163 Firmware Subscribe
Xm7170 Firmware Subscribe
Xm7263 Firmware Subscribe
Xm7270 Firmware Subscribe
Xm9145 Firmware Subscribe
Xm9155 Firmware Subscribe
Xm9165 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44836 Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-01T14:26:17.023Z

Reserved: 2023-08-11T00:00:00

Link: CVE-2023-40239

cve-icon Vulnrichment

Updated: 2024-08-02T18:24:55.807Z

cve-icon NVD

Status : Modified

Published: 2023-09-01T11:15:42.657

Modified: 2024-11-21T08:19:03.160

Link: CVE-2023-40239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses