7.5

CVE-2023-40239

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LexmarkC2132 Firmware Version <= lw80.vy4.p245
   LexmarkC2132 Version-
LexmarkCs310 Firmware Version <= lw80.vyl.p245
   LexmarkCs310 Version-
LexmarkCs317 Firmware Version <= lw80.vyl.p245
   LexmarkCs317 Version-
LexmarkCs410 Firmware Version <= lw80.vy2.p245
   LexmarkCs410 Version-
LexmarkCs417 Firmware Version <= lw80.vy2.p245
   LexmarkCs417 Version-
LexmarkCs510 Firmware Version <= lw80.vy4.p245
   LexmarkCs510 Version-
LexmarkCs517 Firmware Version <= lw80.vy4.p245
   LexmarkCs517 Version-
LexmarkCx310 Firmware Version <= lw80.gm2.p245
   LexmarkCx310 Version-
LexmarkCx317 Firmware Version <= lw80.gm2.p245
   LexmarkCx317 Version-
LexmarkCx410 Firmware Version <= lw80.gm4.p245
   LexmarkCx410 Version-
LexmarkCx417 Firmware Version <= lw80.gm4.p245
   LexmarkCx417 Version-
LexmarkCx510 Firmware Version <= lw80.gm7.p245
   LexmarkCx510 Version-
LexmarkCx517 Firmware Version <= lw80.gm7.p245
   LexmarkCx517 Version-
LexmarkM1140+ Firmware Version <= lw80.pr2.p245
   LexmarkM1140+ Version-
LexmarkM1140 Firmware Version <= lw80.prl.p245
   LexmarkM1140 Version-
LexmarkM1145 Firmware Version <= lw80.pr2.p245
   LexmarkM1145 Version-
LexmarkM3150de Firmware Version <= lw80.pr4.p245
   LexmarkM3150de Version-
LexmarkM3150dn Firmware Version <= lw80.pr2.p245
   LexmarkM3150dn Version-
LexmarkM5155 Firmware Version <= lw80.dn4.p245
   LexmarkM5155 Version-
LexmarkM5163de Firmware Version <= lw80.dn4.p245
   LexmarkM5163de Version-
LexmarkM5163dn Firmware Version <= lw80.dn2.p245
   LexmarkM5163dn Version-
LexmarkM5170 Firmware Version <= lw80.dn7.p245
   LexmarkM5170 Version-
LexmarkMs310 Firmware Version <= lw80.prl.p245
   LexmarkMs310 Version-
LexmarkMs312 Firmware Version <= lw80.prl.p245
   LexmarkMs312 Version-
LexmarkMs315 Firmware Version <= lw80.tl2.p245
   LexmarkMs315 Version-
LexmarkMs317 Firmware Version <= lw80.prl.p245
   LexmarkMs317 Version-
LexmarkMs410 Firmware Version <= lw80.prl.p245
   LexmarkMs410 Version-
LexmarkMs415 Firmware Version <= lw80.tl2.p245
   LexmarkMs415 Version-
LexmarkMs417 Firmware Version <= lw80.tl2.p245
   LexmarkMs417 Version-
LexmarkMs510 Firmware Version <= lw80.pr2.p245
   LexmarkMs510 Version-
LexmarkMs517 Firmware Version <= lw80.pr2.p245
   LexmarkMs517 Version-
LexmarkMs610de Firmware Version <= lw80.pr4.p245
   LexmarkMs610de Version-
LexmarkMs610dn Firmware Version <= lw80.pr2.p245
   LexmarkMs610dn Version-
LexmarkMs617 Firmware Version <= lw80.pr2.p245
   LexmarkMs617 Version-
LexmarkMs710 Firmware Version <= lw80.dn2.p245
   LexmarkMs710 Version-
LexmarkMs711 Firmware Version <= lw80.dn2.p245
   LexmarkMs711 Version-
LexmarkMs810de Firmware Version <= lw80.dn4.p245
   LexmarkMs810de Version-
LexmarkMs810dn Firmware Version <= lw80.dn2.p245
   LexmarkMs810dn Version-
LexmarkMs811 Firmware Version <= lw80.dn2.p245
   LexmarkMs811 Version-
LexmarkMs812de Firmware Version <= lw80.dn7.p245
   LexmarkMs812de Version-
LexmarkMs812dn Firmware Version <= lw80.dn2.p245
   LexmarkMs812dn Version-
LexmarkMs817 Firmware Version <= lw80.dn2.p245
   LexmarkMs817 Version-
LexmarkMs818 Firmware Version <= lw80.dn2.p245
   LexmarkMs818 Version-
LexmarkMs911 Firmware Version <= lw80.sa.p245
   LexmarkMs911 Version-
LexmarkMx310 Firmware Version <= lw80.sb2.p245
   LexmarkMx310 Version-
LexmarkMx317 Firmware Version <= lw80.sb2.p245
   LexmarkMx317 Version-
LexmarkMx410 Firmware Version <= lw80.sb4.p245
   LexmarkMx410 Version-
LexmarkMx417 Firmware Version <= lw80.sb4.p245
   LexmarkMx417 Version-
LexmarkMx510 Firmware Version <= lw80.sb4.p245
   LexmarkMx510 Version-
LexmarkMx511 Firmware Version <= lw80.sb4.p245
   LexmarkMx511 Version-
LexmarkMx517 Firmware Version <= lw80.sb4.p245
   LexmarkMx517 Version-
LexmarkMx610 Firmware Version <= lw80.sb7.p245
   LexmarkMx610 Version-
LexmarkMx611 Firmware Version <= lw80.sb7.p245
   LexmarkMx611 Version-
LexmarkMx617 Firmware Version <= lw80.sb7.p245
   LexmarkMx617 Version-
LexmarkMx710 Firmware Version <= lw80.tu.p245
   LexmarkMx710 Version-
LexmarkMx711 Firmware Version <= lw80.tu.p245
   LexmarkMx711 Version-
LexmarkMx717 Firmware Version <= lw80.tu.p245
   LexmarkMx717 Version-
LexmarkMx718 Firmware Version <= lw80.tu.p245
   LexmarkMx718 Version-
LexmarkMx810 Firmware Version <= lw80.tu.p245
   LexmarkMx810 Version-
LexmarkMx811 Firmware Version <= lw80.tu.p245
   LexmarkMx811 Version-
LexmarkMx812 Firmware Version <= lw80.tu.p245
   LexmarkMx812 Version-
LexmarkMx910 Firmware Version <= lw80.mg.p245
   LexmarkMx910 Version-
LexmarkMx911 Firmware Version <= lw80.mg.p245
   LexmarkMx911 Version-
LexmarkMx912 Firmware Version <= lw80.mg.p245
   LexmarkMx912 Version-
LexmarkXc2130 Firmware Version <= lw80.gm4.p245
   LexmarkXc2130 Version-
LexmarkXc2132 Firmware Version <= lw80.gm7.p245
   LexmarkXc2132 Version-
LexmarkXm1135 Firmware Version <= lw80.sb2.p245
   LexmarkXm1135 Version-
LexmarkXm1140 Firmware Version <= lw80.sb4.p245
   LexmarkXm1140 Version-
LexmarkXm1145 Firmware Version <= lw80.sb4.p245
   LexmarkXm1145 Version-
LexmarkXm3150 Firmware Version <= lw80.sb7.p245
   LexmarkXm3150 Version-
LexmarkXm5163 Firmware Version <= lw80.tu.p245
   LexmarkXm5163 Version-
LexmarkXm5170 Firmware Version <= lw80.tu.p245
   LexmarkXm5170 Version-
LexmarkXm5263 Firmware Version <= lw80.tu.p245
   LexmarkXm5263 Version-
LexmarkXm5270 Firmware Version <= lw80.tu.p245
   LexmarkXm5270 Version-
LexmarkXm7155 Firmware Version <= lw80.tu.p245
   LexmarkXm7155 Version-
LexmarkXm7163 Firmware Version <= lw80.tu.p245
   LexmarkXm7163 Version-
LexmarkXm7170 Firmware Version <= lw80.tu.p245
   LexmarkXm7170 Version-
LexmarkXm7263 Firmware Version <= lw80.tu.p245
   LexmarkXm7263 Version-
LexmarkXm7270 Firmware Version <= lw80.tu.p245
   LexmarkXm7270 Version-
LexmarkXm9145 Firmware Version <= lw80.mg.p245
   LexmarkXm9145 Version-
LexmarkXm9155 Firmware Version <= lw80.mg.p245
   LexmarkXm9155 Version-
LexmarkXm9165 Firmware Version <= lw80.mg.p245
   LexmarkXm9165 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.43
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.