CVE-2023-40239
Published Sep 1, 2023Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that…
Vendor/product archive
17 CVEs tagged to lexmark / cx310 — 5 Critical, 2 High, 10 Medium, 0 Low, 0 Unrated.
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that…
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC213…
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?p…
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/inde…
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose sessio…
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.
Various Lexmark products have an Integer Overflow.
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
Various Lexmark products have CSRF.
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Various Lexmark products have Incorrect Access Control.
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.