CVE-2023-40239

HIGH

Lexmark Printers Firmware < LW80.*.P246 - XXE Injection

Title source: llm
STIX 2.1

Description

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (50)
lexmark/c2132_firmware < lw80.vy4.p245
lexmark/cs310_firmware < lw80.vyl.p245
lexmark/cs317_firmware < lw80.vyl.p245
lexmark/cs410_firmware < lw80.vy2.p245
lexmark/cs417_firmware < lw80.vy2.p245
lexmark/cs510_firmware < lw80.vy4.p245
lexmark/cs517_firmware < lw80.vy4.p245
lexmark/cx310_firmware < lw80.gm2.p245
lexmark/cx317_firmware < lw80.gm2.p245
lexmark/cx410_firmware < lw80.gm4.p245
... and 40 more
Published Sep 01, 2023
Tracked Since Feb 18, 2026