Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lexmark
Subscribe
|
C2132
Subscribe
C2132 Firmware
Subscribe
Cs310
Subscribe
Cs310 Firmware
Subscribe
Cs317
Subscribe
Cs317 Firmware
Subscribe
Cs410
Subscribe
Cs410 Firmware
Subscribe
Cs417
Subscribe
Cs417 Firmware
Subscribe
Cs510
Subscribe
Cs510 Firmware
Subscribe
Cs517
Subscribe
Cs517 Firmware
Subscribe
Cx310
Subscribe
Cx310 Firmware
Subscribe
Cx317
Subscribe
Cx317 Firmware
Subscribe
Cx410
Subscribe
Cx410 Firmware
Subscribe
Cx417
Subscribe
Cx417 Firmware
Subscribe
Cx510
Subscribe
Cx510 Firmware
Subscribe
Cx517
Subscribe
Cx517 Firmware
Subscribe
M1140
Subscribe
M1140\+
Subscribe
M1140\+ Firmware
Subscribe
M1140 Firmware
Subscribe
M1145
Subscribe
M1145 Firmware
Subscribe
M3150de
Subscribe
M3150de Firmware
Subscribe
M3150dn
Subscribe
M3150dn Firmware
Subscribe
M5155
Subscribe
M5155 Firmware
Subscribe
M5163de
Subscribe
M5163de Firmware
Subscribe
M5163dn
Subscribe
M5163dn Firmware
Subscribe
M5170
Subscribe
M5170 Firmware
Subscribe
Ms310
Subscribe
Ms310 Firmware
Subscribe
Ms312
Subscribe
Ms312 Firmware
Subscribe
Ms315
Subscribe
Ms315 Firmware
Subscribe
Ms317
Subscribe
Ms317 Firmware
Subscribe
Ms410
Subscribe
Ms410 Firmware
Subscribe
Ms415
Subscribe
Ms415 Firmware
Subscribe
Ms417
Subscribe
Ms417 Firmware
Subscribe
Ms510
Subscribe
Ms510 Firmware
Subscribe
Ms517
Subscribe
Ms517 Firmware
Subscribe
Ms610de
Subscribe
Ms610de Firmware
Subscribe
Ms610dn
Subscribe
Ms610dn Firmware
Subscribe
Ms617
Subscribe
Ms617 Firmware
Subscribe
Ms710
Subscribe
Ms710 Firmware
Subscribe
Ms711
Subscribe
Ms711 Firmware
Subscribe
Ms810de
Subscribe
Ms810de Firmware
Subscribe
Ms810dn
Subscribe
Ms810dn Firmware
Subscribe
Ms811
Subscribe
Ms811 Firmware
Subscribe
Ms812de
Subscribe
Ms812de Firmware
Subscribe
Ms812dn
Subscribe
Ms812dn Firmware
Subscribe
Ms817
Subscribe
Ms817 Firmware
Subscribe
Ms818
Subscribe
Ms818 Firmware
Subscribe
Ms911
Subscribe
Ms911 Firmware
Subscribe
Mx310
Subscribe
Mx310 Firmware
Subscribe
Mx317
Subscribe
Mx317 Firmware
Subscribe
Mx410
Subscribe
Mx410 Firmware
Subscribe
Mx417
Subscribe
Mx417 Firmware
Subscribe
Mx510
Subscribe
Mx510 Firmware
Subscribe
Mx511
Subscribe
Mx511 Firmware
Subscribe
Mx517
Subscribe
Mx517 Firmware
Subscribe
Mx610
Subscribe
Mx610 Firmware
Subscribe
Mx611
Subscribe
Mx611 Firmware
Subscribe
Mx617
Subscribe
Mx617 Firmware
Subscribe
Mx710
Subscribe
Mx710 Firmware
Subscribe
Mx711
Subscribe
Mx711 Firmware
Subscribe
Mx717
Subscribe
Mx717 Firmware
Subscribe
Mx718
Subscribe
Mx718 Firmware
Subscribe
Mx810
Subscribe
Mx810 Firmware
Subscribe
Mx811
Subscribe
Mx811 Firmware
Subscribe
Mx812
Subscribe
Mx812 Firmware
Subscribe
Mx910
Subscribe
Mx910 Firmware
Subscribe
Mx911
Subscribe
Mx911 Firmware
Subscribe
Mx912
Subscribe
Mx912 Firmware
Subscribe
Xc2130
Subscribe
Xc2130 Firmware
Subscribe
Xc2132
Subscribe
Xc2132 Firmware
Subscribe
Xm1135
Subscribe
Xm1135 Firmware
Subscribe
Xm1140
Subscribe
Xm1140 Firmware
Subscribe
Xm1145
Subscribe
Xm1145 Firmware
Subscribe
Xm3150
Subscribe
Xm3150 Firmware
Subscribe
Xm5163
Subscribe
Xm5163 Firmware
Subscribe
Xm5170
Subscribe
Xm5170 Firmware
Subscribe
Xm5263
Subscribe
Xm5263 Firmware
Subscribe
Xm5270
Subscribe
Xm5270 Firmware
Subscribe
Xm7155
Subscribe
Xm7155 Firmware
Subscribe
Xm7163
Subscribe
Xm7163 Firmware
Subscribe
Xm7170
Subscribe
Xm7170 Firmware
Subscribe
Xm7263
Subscribe
Xm7263 Firmware
Subscribe
Xm7270
Subscribe
Xm7270 Firmware
Subscribe
Xm9145
Subscribe
Xm9145 Firmware
Subscribe
Xm9155
Subscribe
Xm9155 Firmware
Subscribe
Xm9165
Subscribe
Xm9165 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44836 | Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-01T14:26:17.023Z
Reserved: 2023-08-11T00:00:00
Link: CVE-2023-40239
Updated: 2024-08-02T18:24:55.807Z
Status : Modified
Published: 2023-09-01T11:15:42.657
Modified: 2024-11-21T08:19:03.160
Link: CVE-2023-40239
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD