2023-09-01 12:00:28 +00:00

20 lines
773 B
JSON

{
"id": "CVE-2023-40239",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-09-01T11:15:42.657",
"lastModified": "2023-09-01T11:47:43.290",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability."
}
],
"metrics": {},
"references": [
{
"url": "https://publications.lexmark.com/publications/security-alerts/CVE-2023-40239.pdf",
"source": "cve@mitre.org"
}
]
}