PT-2023-27344 · Lexmark · Lexmark
Published
2023-09-01
·
Updated
2023-09-12
·
CVE-2023-40239
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lexmark devices versions prior to LW80.*.P246
Description
The issue allows XXE attacks, leading to information disclosure. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include XXE attacks.
Recommendations
For Lexmark devices versions prior to LW80..P246, update the firmware to LW80..P246 or higher to remediate the vulnerability. As a temporary workaround, consider restricting access to vulnerable components until a patch is available. Avoid using vulnerable functions or parameters in the affected devices until the issue is resolved.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lexmark