CVE-2023-40239: Lexmark c2132 Firmware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Affected products
- Lexmark c2132 Firmware: up to and including lw80.vy4.p245
- Lexmark CS310 Firmware: up to and including lw80.vyl.p245
- Lexmark CS317 Firmware: up to and including lw80.vyl.p245
- Lexmark CS410 Firmware: up to and including lw80.vy2.p245
- Lexmark CS417 Firmware: up to and including lw80.vy2.p245
- Lexmark CS510 Firmware: up to and including lw80.vy4.p245
- Lexmark CS517 Firmware: up to and including lw80.vy4.p245
- Lexmark CX310 Firmware: up to and including lw80.gm2.p245
- Lexmark CX317 Firmware: up to and including lw80.gm2.p245
- Lexmark CX410 Firmware: up to and including lw80.gm4.p245
- Lexmark CX417 Firmware: up to and including lw80.gm4.p245
- Lexmark CX510 Firmware: up to and including lw80.gm7.p245
- Lexmark CX517 Firmware: up to and including lw80.gm7.p245
- Lexmark m1140+ Firmware: up to and including lw80.pr2.p245
- Lexmark m1140 Firmware: up to and including lw80.prl.p245
- Lexmark m1145 Firmware: up to and including lw80.pr2.p245
- Lexmark m3150de Firmware: up to and including lw80.pr4.p245
- Lexmark m3150dn Firmware: up to and including lw80.pr2.p245
- Lexmark m5155 Firmware: up to and including lw80.dn4.p245
- Lexmark m5163de Firmware: up to and including lw80.dn4.p245
- Lexmark m5163dn Firmware: up to and including lw80.dn2.p245
- Lexmark m5170 Firmware: up to and including lw80.dn7.p245
- Lexmark MS310 Firmware: up to and including lw80.prl.p245
- Lexmark MS312 Firmware: up to and including lw80.prl.p245
- Lexmark MS315 Firmware: up to and including lw80.tl2.p245
- and 57 more
Published 2023-09-01. Last modified 2026-06-17.