Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwqw-75wv-wxpm

Опубликовано: 01 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80..P246, i.e., '' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80..P246, i.e., '' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

EPSS

Процентиль: 43%
0.00206
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.

EPSS

Процентиль: 43%
0.00206
Низкий

7.5 High

CVSS3

Дефекты

CWE-611