HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions
Published Jan 23, 2018
6.1
MEDIUMCVSS 3.0
EPSS 1.24%
Description
HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be exploited to perform a cross site scripting (XSS) attack.
Affected products
-
- Version 2308214_000901, 2308214_000900, and other firmware versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HP Inc. | n/a | n/a |
|
Configuration 1
- < 2308214_000901
Configuration 2
- < 2308214_000901
Configuration 3
- < 2308214_000901
Configuration 4
- < 2308214_000900
Configuration 5
- < 2308214_000900
Configuration 6
- < 2308214_000900
Configuration 7
- < 2308214_000904
Configuration 8
- < 2308214_000904
Configuration 9
- < 2308214_000904
Configuration 10
- < 2308214_000926
Configuration 11
- < 2308214_000926
Configuration 12
- < 2308214_000926
Configuration 13
- < 2308214_000926
Configuration 14
- < 2308214_000926
Configuration 15
- < 2308214_000926
Configuration 16
- < 2308214_000926
Configuration 17
- < 2308214_000926
Configuration 18
- < 2308214_000927
Configuration 19
- < 2308214_000927
Configuration 20
- < 2308214_000927
Configuration 21
- < 2308214_000903
Configuration 22
- < 2308214_000925
Configuration 23
- < 2308214_000925
Configuration 24
- < 2308214_000913
Configuration 25
- < 2308214_000913
Configuration 26
- < 2308214_000932
Configuration 27
- < 2308214_000932
Configuration 28
- < 2308214_000932
Configuration 29
- < 2308214_000922
Configuration 30
- < 2308214_000922
Configuration 31
- < 2308214_000922
Configuration 32
- < 2308214_000925
Configuration 33
- < 2308214_000913
Configuration 34
- < 2308214_000921
Configuration 35
- < 2308214_000921
Configuration 36
- < 2308214_000921
Configuration 37
- < 2308214_000921
Configuration 38
- < 2308214_000931
Configuration 39
- < 2308214_000931
Configuration 40
- < 2308214_000931
Configuration 41
- < 2308214_000930
Configuration 42
- < 2308214_000930
Configuration 43
- < 2308214_000930
Configuration 44
- < 2308214_000928
Configuration 45
- < 2308214_000928
Configuration 46
- < 2308214_000928
Configuration 47
- < 2308214_000928
Configuration 48
- < 2308214_000916
Configuration 49
- < 2308214_000920
Configuration 50
- < 2308214_000920
Configuration 51
- < 2308214_000902
Configuration 52
- < 2308214_000902
Configuration 53
- < 2308214_000902
Configuration 54
- < 2308214_000906
Configuration 55
- < 2308214_000906
Configuration 56
- < _2308214_000912
Configuration 57
- < 2308214_000907
Configuration 58
- < 2308214_000907
Configuration 59
- < 2308214_000907
Configuration 60
- < 2308214_000907
Configuration 61
- < 2308214_000908
Configuration 62
- < 2308214_000908
Configuration 63
- < 2308214_000908
Configuration 64
- < 2308214_000908
Configuration 65
- < _2308214_000908
Configuration 66
- < 2308214_000908
Configuration 67
- < 2308214_000908
Configuration 68
- < 2308214_000912
Configuration 69
- < 2308214_000909
Configuration 70
- < 2308214_000909
Configuration 71
- < 2308214_000909
Configuration 72
- < 2308214_000911
Configuration 73
- < 2308214_000911
Configuration 74
- < 2308214_000911
Configuration 75
- < 2308214_000911
Configuration 76
- < 2308214_000905
Configuration 77
- < 2308214_000905
Configuration 78
- < 2308214_000905
Configuration 79
- < 2308214_000910
Configuration 80
- < 2308214_000910
Configuration 81
- < 2308214_000910
Configuration 82
- < 2308214_000910
Configuration 83
- < 2308214_000910
Configuration 84
- < 2308214_000923
Configuration 85
- < 2308214_000923
Configuration 86
- < 2308214_000923
Configuration 87
- < 2308214_000923
Configuration 88
- < 2308214_000923
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.24% (0.01242) | 68.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.27% (0.01266) | 65.79th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.02% (0.01020) | 75.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00067) | 31.67th | v3 (v2023.03.01) |
| May 22, 2024 | 0.07% (0.00067) | 29.27th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.07% (0.00067) | 27.19th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00058) | 22.55th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.06% (0.02063) | 50.26th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.06% (0.02063) | 0.00th | v1 |
References (1)
- https://support.hp.com/us-en/document/c05541569 vendor-advisoryx_refsource_HPVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.hp.com/us-en/document/c05541569 | vendor-advisoryx_refsource_HPVendor Advisory |
Change history (0)
No recorded changes yet.