A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions
Published Oct 3, 2018
8.8
HIGHCVSS 3.0
EPSS 0.74%
Description
A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.
Affected products
- Vendor HP Inc. Product Certain HP Enterprise Printers, HP PageWide Printers, and MFP Products Defaultn/a
- Version 2405129_000052 and other firmware versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HP Inc. | Certain HP Enterprise Printers, HP PageWide Printers, and MFP Products | n/a |
|
Configuration 1
- < 2405129_000052
Configuration 2
- < 2405129_000052
Configuration 3
- < 2405129_000052
Configuration 4
- < 2405129_000056
Configuration 5
- < 2405129_000056
Configuration 6
- < 2405129_000055
Configuration 7
- < 2405129_000055
Configuration 8
- < 2405129_000055
Configuration 9
- < 2405129_000055
Configuration 10
- < 2405129_000055
Configuration 11
- < 2405129_000051
Configuration 12
- < 2405129_000051
Configuration 13
- < 2405129_000051
Configuration 14
- < 2405129_000051
Configuration 15
- < 2405129_000051
Configuration 16
- < 2405135_000394
Configuration 17
- < 2405129_000046
Configuration 18
- < 2405129_000046
Configuration 19
- < 2405130_000069
Configuration 20
- < 2405130_000069
Configuration 21
- < 2405130_000069
Configuration 22
- < 2405130_000069
Configuration 23
- < 2405130_000069
Configuration 24
- < 2405130_000069
Configuration 25
- < 2405130_000069
Configuration 26
- < 2405130_000069
Configuration 27
- < 2405130_000069
Configuration 28
- < 2405130_000069
Configuration 29
- < 2405130_000069
Configuration 30
- < 2405130_000069
Configuration 31
- < 2405130_000069
Configuration 32
- < 2405130_000069
Configuration 33
- < 2405129_000047
Configuration 34
- < 2405129_000047
Configuration 35
- < 2405130_000068
Configuration 36
- < 2405130_000068
Configuration 37
- < 2405130_000068
Configuration 38
- < 2405130_000068
Configuration 39
- < 2405130_000068
Configuration 40
- < 2405130_000068
Configuration 41
- < 2405130_000068
Configuration 42
- < 2405130_000068
Configuration 43
- < 2405087_018564
Configuration 44
- < 2405087_018564
Configuration 45
- < 2405129_000059
Configuration 46
- < 2405129_000057
Configuration 47
- < 2405129_000059
Configuration 48
- < 2405129_000057
Configuration 49
- < 2405129_000057
Configuration 50
- < 2405129_000057
Configuration 51
- < 2405129_000048
Configuration 52
- < 2405129_000048
Configuration 53
- < 2405129_000048
Configuration 54
- < 2405129_000048
Configuration 56
- < 2405129_000039
Configuration 57
- < 2405129_000039
Configuration 58
- < 2405129_000039
Configuration 59
- < 2405129_000039
Configuration 60
- < 2405129_000039
Configuration 61
- < 2405129_000039
Configuration 62
- < 2405135_000409
Configuration 63
- < 2405135_000409
Configuration 64
- < 2405129_000045
Configuration 65
- < 2405129_000045
Configuration 66
- < 2405129_000045
Configuration 67
- < 2405129_000038
Configuration 68
- < 2405129_000038
Configuration 69
- < 2405129_000038
Configuration 70
- < 2405129_000038
Configuration 71
- < 2405129_000038
Configuration 72
- < 2405129_000038
Configuration 73
- < 2405129_000050
Configuration 74
- < 2405129_000050
Configuration 75
- < 2405129_000050
Configuration 76
- < 2405129_000050
Configuration 77
- < 2405129_000050
Configuration 78
- < 2405129_000050
Configuration 79
- < 2405129_000066
Configuration 80
- < 2405129_000066
Configuration 81
- < 2405129_000066
Configuration 82
- < 2405129_000066
Configuration 83
- < 2405129_000066
Configuration 84
- < 2405129_000066
Configuration 85
- < 2405129_000066
Configuration 86
- < 2405129_000066
Configuration 87
- < 2405129_000040
Configuration 88
- < 2405129_000040
Configuration 89
- < 2405129_000040
Configuration 90
- < 2405129_000040
Configuration 91
- < 2405129_000040
Configuration 92
- < 2405129_000040
Configuration 93
- < 2405129_000040
Configuration 94
- < 2405129_000040
Configuration 95
- < 2405129_000041
Configuration 96
- < 2405129_000041
Configuration 97
- < 2405129_000041
Configuration 98
- < 2405129_000041
Configuration 99
- < 2405129_000041
Configuration 100
- < 2405129_000041
Configuration 101
- < 2405129_000041
Configuration 102
- < 2405129_000041
Configuration 103
- < 2405129_000041
Configuration 104
- < 2405129_000041
Configuration 105
- < 2405129_000041
Configuration 106
- < 2405129_000041
Configuration 107
- < 2405129_000041
Configuration 108
- < 2405129_000041
Configuration 109
- < 2405129_000042
Configuration 110
- < 2405129_000042
Configuration 111
- < 2405129_000042
Configuration 112
- < 2405129_000042
Configuration 113
- < 2405129_000042
Configuration 114
- < 2405129_000042
Configuration 115
- < 2405129_000037
Configuration 116
- < 2405129_000037
Configuration 117
- < 2405129_000037
Configuration 118
- < 2405129_000037
Configuration 119
- < 2405129_000037
Configuration 120
- < 2405129_000037
Configuration 121
- < 2405129_000037
Configuration 122
- < 2405129_000037
Configuration 123
- < 2405129_000037
Configuration 124
- < 2405129_000037
Configuration 125
- < 2405129_000058
Configuration 126
- < 2405129_000058
Configuration 127
- < 2405129_000058
Configuration 128
- < 2405129_000058
Configuration 129
- < 2405129_000058
Configuration 130
- < 2405129_000058
Configuration 131
- < 2405135_000405
Configuration 132
- < 2405135_000405
Configuration 133
- < 2405135_000405
Configuration 134
- < 2405135_000405
Configuration 135
- < 2405135_000405
Configuration 136
- < 2405129_000060
Configuration 137
- < 2405129_000060
Configuration 138
- < 2405129_000060
Configuration 139
- < 2405129_000054
Configuration 140
- < 2405129_000054
Configuration 141
- < 2405129_000054
Configuration 142
- < 2405129_000054
Configuration 143
- < 2405129_000054
Configuration 144
- < 2405129_000054
Configuration 145
- < 2405129_000054
Configuration 146
- < 2405129_000054
Configuration 147
- < 2405347_024815
Configuration 148
- < 2405347_024815
Configuration 149
- < 2405347_024815
Configuration 150
- < 2405347_024815
Configuration 151
- < 2405347_024815
Configuration 152
- < 2405347_024815
Configuration 153
- < 2405347_024815
Configuration 154
- < 2405347_024815
Configuration 155
- < 2405347_024815
Configuration 156
- < 2405347_024815
Configuration 157
- < 2405347_024815
Configuration 158
- < 2405347_024815
Configuration 159
- < 2405347_024815
Configuration 160
- < 2405347_024821
Configuration 161
- < 2405347_024821
Configuration 162
- < 2405347_024821
Configuration 163
- < 2405347_024821
Configuration 164
- < 2405347_024821
Configuration 165
- < 2405347_024821
Configuration 166
- < 2405347_024821
Configuration 167
- < 2405347_024821
Configuration 168
- < 2405347_024821
Configuration 169
- < 2405347_024821
Configuration 170
- < 2405347_024821
Configuration 171
- < 2405347_024821
Configuration 172
- < 2405347_024814
Configuration 173
- < 2405347_024814
Configuration 174
- < 2405347_024814
Configuration 175
- < 2405347_024814
Configuration 176
- < 2405347_024814
Configuration 177
- < 2405347_024814
Configuration 178
- < 2405347_024814
Configuration 179
- < 2405347_024814
Configuration 180
- < 2405347_024814
Configuration 181
- < 2405347_024814
Configuration 182
- < 2405347_024814
Configuration 183
- < 2405347_024814
Configuration 184
- < 2405347_024820
Configuration 185
- < 2405347_024820
Configuration 186
- < 2405347_024820
Configuration 187
- < 2405347_024820
Configuration 188
- < 2405347_024820
Configuration 189
- < 2405347_024820
Configuration 190
- < 2405347_024820
Configuration 191
- < 2405347_024820
Configuration 192
- < 2405347_024820
Configuration 193
- < 2405347_024820
Configuration 194
- < 2405347_024820
Configuration 195
- < 2405347_024820
Configuration 196
- < 2405087_018553
Configuration 197
- < 2405087_018552
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.74% (0.00741) | 53.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.74% (0.00741) | 49.64th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.22% (0.00217) | 42.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00073) | 33.58th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.07% (0.00073) | 31.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00073) | 29.58th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.06% (0.02063) | 50.26th | v1 |
| Jan 6, 2022 | 2.06% (0.02063) | 49.75th | v1 |
| Sep 1, 2021 | 2.06% (0.02063) | 76.98th | v1 |
| Apr 14, 2021 | 2.06% (0.02063) | 0.00th | v1 |
References (1)
- https://support.hp.com/us-en/document/c05949322 vendor-advisoryx_refsource_HPVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.hp.com/us-en/document/c05949322 | vendor-advisoryx_refsource_HPVendor Advisory |
Change history (0)
No recorded changes yet.