Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Conclusion & alert: CVE-2023-40239 is rated Moderate Risk (47.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-04 | 0.24% | 0.27% | +0.03% |
| 2 | 2025-03-30 | 0.46% | 0.24% | -0.22% |
| 3 | 2025-03-29 | — | 0.46% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lexmark | c2132_firmware | <= lw80.vy4.p245 | cpe:2.3:o:lexmark:c2132_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs310_firmware | <= lw80.vyl.p245 | cpe:2.3:o:lexmark:cs310_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs317_firmware | <= lw80.vyl.p245 | cpe:2.3:o:lexmark:cs317_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs410_firmware | <= lw80.vy2.p245 | cpe:2.3:o:lexmark:cs410_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs417_firmware | <= lw80.vy2.p245 | cpe:2.3:o:lexmark:cs417_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs510_firmware | <= lw80.vy4.p245 | cpe:2.3:o:lexmark:cs510_firmware:*:*:*:*:*:*:*:* |
| lexmark | cs517_firmware | <= lw80.vy4.p245 | cpe:2.3:o:lexmark:cs517_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx310_firmware | <= lw80.gm2.p245 | cpe:2.3:o:lexmark:cx310_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx317_firmware | <= lw80.gm2.p245 | cpe:2.3:o:lexmark:cx317_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx410_firmware | <= lw80.gm4.p245 | cpe:2.3:o:lexmark:cx410_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx417_firmware | <= lw80.gm4.p245 | cpe:2.3:o:lexmark:cx417_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx510_firmware | <= lw80.gm7.p245 | cpe:2.3:o:lexmark:cx510_firmware:*:*:*:*:*:*:*:* |
| lexmark | cx517_firmware | <= lw80.gm7.p245 | cpe:2.3:o:lexmark:cx517_firmware:*:*:*:*:*:*:*:* |
| lexmark | m1140\+_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:m1140\+_firmware:*:*:*:*:*:*:*:* |
| lexmark | m1140_firmware | <= lw80.prl.p245 | cpe:2.3:o:lexmark:m1140_firmware:*:*:*:*:*:*:*:* |
| lexmark | m1145_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:m1145_firmware:*:*:*:*:*:*:*:* |
| lexmark | m3150de_firmware | <= lw80.pr4.p245 | cpe:2.3:o:lexmark:m3150de_firmware:*:*:*:*:*:*:*:* |
| lexmark | m3150dn_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:m3150dn_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5155_firmware | <= lw80.dn4.p245 | cpe:2.3:o:lexmark:m5155_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5163de_firmware | <= lw80.dn4.p245 | cpe:2.3:o:lexmark:m5163de_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5163dn_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:m5163dn_firmware:*:*:*:*:*:*:*:* |
| lexmark | m5170_firmware | <= lw80.dn7.p245 | cpe:2.3:o:lexmark:m5170_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms310_firmware | <= lw80.prl.p245 | cpe:2.3:o:lexmark:ms310_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms312_firmware | <= lw80.prl.p245 | cpe:2.3:o:lexmark:ms312_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms315_firmware | <= lw80.tl2.p245 | cpe:2.3:o:lexmark:ms315_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms317_firmware | <= lw80.prl.p245 | cpe:2.3:o:lexmark:ms317_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms410_firmware | <= lw80.prl.p245 | cpe:2.3:o:lexmark:ms410_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms415_firmware | <= lw80.tl2.p245 | cpe:2.3:o:lexmark:ms415_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms417_firmware | <= lw80.tl2.p245 | cpe:2.3:o:lexmark:ms417_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms510_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:ms510_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms517_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:ms517_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms610de_firmware | <= lw80.pr4.p245 | cpe:2.3:o:lexmark:ms610de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms610dn_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:ms610dn_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms617_firmware | <= lw80.pr2.p245 | cpe:2.3:o:lexmark:ms617_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms710_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms710_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms711_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms711_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms810de_firmware | <= lw80.dn4.p245 | cpe:2.3:o:lexmark:ms810de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms810dn_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms810dn_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms811_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms811_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms812de_firmware | <= lw80.dn7.p245 | cpe:2.3:o:lexmark:ms812de_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms812dn_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms812dn_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms817_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms817_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms818_firmware | <= lw80.dn2.p245 | cpe:2.3:o:lexmark:ms818_firmware:*:*:*:*:*:*:*:* |
| lexmark | ms911_firmware | <= lw80.sa.p245 | cpe:2.3:o:lexmark:ms911_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx310_firmware | <= lw80.sb2.p245 | cpe:2.3:o:lexmark:mx310_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx317_firmware | <= lw80.sb2.p245 | cpe:2.3:o:lexmark:mx317_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx410_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:mx410_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx417_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:mx417_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx510_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:mx510_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx511_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:mx511_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx517_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:mx517_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx610_firmware | <= lw80.sb7.p245 | cpe:2.3:o:lexmark:mx610_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx611_firmware | <= lw80.sb7.p245 | cpe:2.3:o:lexmark:mx611_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx617_firmware | <= lw80.sb7.p245 | cpe:2.3:o:lexmark:mx617_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx710_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx710_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx711_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx711_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx717_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx717_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx718_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx718_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx810_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx810_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx811_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx811_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx812_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:mx812_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx910_firmware | <= lw80.mg.p245 | cpe:2.3:o:lexmark:mx910_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx911_firmware | <= lw80.mg.p245 | cpe:2.3:o:lexmark:mx911_firmware:*:*:*:*:*:*:*:* |
| lexmark | mx912_firmware | <= lw80.mg.p245 | cpe:2.3:o:lexmark:mx912_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc2130_firmware | <= lw80.gm4.p245 | cpe:2.3:o:lexmark:xc2130_firmware:*:*:*:*:*:*:*:* |
| lexmark | xc2132_firmware | <= lw80.gm7.p245 | cpe:2.3:o:lexmark:xc2132_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm1135_firmware | <= lw80.sb2.p245 | cpe:2.3:o:lexmark:xm1135_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm1140_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:xm1140_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm1145_firmware | <= lw80.sb4.p245 | cpe:2.3:o:lexmark:xm1145_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm3150_firmware | <= lw80.sb7.p245 | cpe:2.3:o:lexmark:xm3150_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5163_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm5163_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5170_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm5170_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5263_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm5263_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm5270_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm5270_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7155_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm7155_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7163_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm7163_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7170_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm7170_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7263_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm7263_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm7270_firmware | <= lw80.tu.p245 | cpe:2.3:o:lexmark:xm7270_firmware:*:*:*:*:*:*:*:* |
| lexmark | xm9145_firmware | <= lw80.mg.p245 | cpe:2.3:o:lexmark:xm9145_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://publications.lexmark.com/publications/security-alerts/CVE-2023-40239.pdf | Vendor Advisory |