CVE-2023-40239
HIGHLexmark Printers Firmware < LW80.*.P246 - XXE Injection
Title source: llmDescription
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0045
EPSS Percentile
35.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-611
Status
published
Products (50)
lexmark/c2132_firmware
< lw80.vy4.p245
lexmark/cs310_firmware
< lw80.vyl.p245
lexmark/cs317_firmware
< lw80.vyl.p245
lexmark/cs410_firmware
< lw80.vy2.p245
lexmark/cs417_firmware
< lw80.vy2.p245
lexmark/cs510_firmware
< lw80.vy4.p245
lexmark/cs517_firmware
< lw80.vy4.p245
lexmark/cx310_firmware
< lw80.gm2.p245
lexmark/cx317_firmware
< lw80.gm2.p245
lexmark/cx410_firmware
< lw80.gm4.p245
... and 40 more
Published
Sep 01, 2023
Tracked Since
Feb 18, 2026