A potential security vulnerability has been identified with certain HP InkJet printers
Published Jan 9, 2020
4.8
MEDIUMCVSS 3.1
EPSS 0.65%
Description
A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink Advantage 2600 All-in-One Printer series model numbers V1N02A - V1N02B, Y5Z00A - Y5Z04B; HP DeskJet Ink Advantage 5000 All-in-One Printer series model numbers M2U86A - M2U89B; HP DeskJet Ink Advantage 5200 All-in-One Printer series model numbers M2U76A - M2U78B; HP ENVY 5000 All-in-One Printer series model numbers M2U85A - M2U85B, M2U91A - M2U94B, Z4A54A - Z4A74A; HP ENVY Photo 6200 All-in-One Printer series model numbers K7G18A-K7G26B, K7S21B, Y0K13D - Y0K15A; HP ENVY Photo 7100 All-in-One Printer series model numbers 3XD89A, K7G93A-K7G99A, Z3M37A - Z3M52A; HP ENVY Photo 7800 All-in-One Printer series model numbers K7R96A, K7S00A - K7S10D, Y0G42D - Y0G52B; HP Ink Tank Wireless 410 series model numbers Z4B53A - Z4B55A, Z6Z95A - Z6Z99A, 4DX94A - 4DX95A, 4YF79A, Z7A01A; HP OfficeJet 5200 All-in-One Printer series model numbers M2U75A, M2U81A-M2U84B, Z4B12A - Z4B14A, Z4B27A - Z4B29A; HP Smart Tank Wireless 450 series model numbers Z4B56A, Z6Z96A - Z6Z98A.
Affected products
-
Affected
- 4UJ28B
- V1N01A - V1N08A
- Y5H60A - Y5H80A
-
Affected
- V1N02A - V1N02B
- Y5Z00A - Y5Z04B
-
Affected
- M2U86A - M2U89B
-
Affected
- M2U76A - M2U78B
-
Affected
- M2U85A - M2U85B
- M2U91A - M2U94B
- Z4A54A - Z4A74A
-
Affected
- K7G18A-K7G26B
- K7S21B
- Y0K13D - Y0K15A
-
Affected
- 3XD89A
- K7G93A-K7G99A
- Z3M37A - Z3M52A
-
Affected
- K7R96A
- K7S00A - K7S10D
- Y0G42D - Y0G52B
-
Affected
- 4DX94A - 4DX95A
- 4YF79A
- Z4B53A - Z4B55A
- Z6Z95A - Z6Z99A
- Z7A01A
-
Affected
- M2U75A
- M2U81A-M2U84B
- Z4B12A - Z4B14A
- Z4B27A - Z4B29A
-
Affected
- Z4B56A
- Z6Z96A - Z6Z98A
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| HP Inc. | HP DeskJet 2600 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP DeskJet Ink Advantage 2600 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP DeskJet Ink Advantage 5000 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP DeskJet Ink Advantage 5200 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP ENVY 5000 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP ENVY Photo 6200 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP ENVY Photo 7100 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP ENVY Photo 7800 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP Ink Tank Wireless 410 series | unknown | Affected
|
| HP Inc. | HP OfficeJet 5200 All-in-One Printer series | unknown | Affected
|
| HP Inc. | HP Smart Tank Wireless 450 series | unknown | Affected
|
Configuration 1
- < 1923
Running on/with
- n/a
Configuration 2
- < 1923
Running on/with
- n/a
Configuration 3
- < 1923
Running on/with
- n/a
Configuration 4
- < 1923
Running on/with
- n/a
Configuration 5
- < 1923
Running on/with
- n/a
Configuration 6
- < 1923
Running on/with
- n/a
Configuration 7
- < 1923
Running on/with
- n/a
Configuration 8
- < 1923
Running on/with
- n/a
Configuration 9
- ≤ 1923
Running on/with
- n/a
Configuration 10
- < 003.1925a
Running on/with
- n/a
Configuration 11
- < 003.1925a
Running on/with
- n/a
Configuration 12
- < 003.1925a
Running on/with
- n/a
Configuration 13
- < 003.1925a
Running on/with
- n/a
Configuration 14
- < 003.1925a
Running on/with
- n/a
Configuration 15
- < 003.1925a
Running on/with
- n/a
Configuration 16
- < 003.1925a
Running on/with
- n/a
Configuration 17
- < 003.1925a
Running on/with
- n/a
Configuration 18
- < 003.1925a
Running on/with
- n/a
Configuration 19
- < 003.1925a
Running on/with
- n/a
Configuration 20
- < 003.1925a
Running on/with
- n/a
Configuration 21
- < 003.1925a
Running on/with
- n/a
Configuration 22
- < 003.1925a
Running on/with
- n/a
Configuration 23
- < 003.1925a
Running on/with
- n/a
Configuration 24
- < 003.1925a
Running on/with
- n/a
Configuration 25
- < 003.1925a
Running on/with
- n/a
Configuration 26
- < 003.1925a
Running on/with
- n/a
Configuration 27
- < 003.1925a
Running on/with
- n/a
Configuration 28
- < 003.1925a
Running on/with
- n/a
Configuration 29
- < 003.1925a
Running on/with
- n/a
Configuration 30
- < 003.1925a
Running on/with
- n/a
Configuration 31
- < 003.1925a
Running on/with
- n/a
Configuration 32
- < 003.1925a
Running on/with
- n/a
Configuration 33
- < 003.1925a
Running on/with
- n/a
Configuration 34
- < 003.1925a
Running on/with
- n/a
Configuration 35
- < 1924
Running on/with
- n/a
Configuration 36
- < 1924
Running on/with
- n/a
Configuration 37
- < 1924
Running on/with
- n/a
Configuration 38
- < 1924
Running on/with
- n/a
Configuration 39
- < 1924
Running on/with
- n/a
Configuration 40
- < 1924
Running on/with
- n/a
Configuration 41
- < 1924
Running on/with
- n/a
Configuration 42
- < 1924
Running on/with
- n/a
Configuration 43
- < 003.1925a
Running on/with
- n/a
Configuration 44
- < 003.1925a
Running on/with
- n/a
Configuration 45
- < 003.1925a
Running on/with
- n/a
Configuration 46
- < 003.1925a
Running on/with
- n/a
Configuration 47
- < 003.1925a
Running on/with
- n/a
Configuration 48
- < 003.1925a
Running on/with
- n/a
Configuration 49
- < 003.1925a
Running on/with
- n/a
Configuration 50
- < 1924
Running on/with
- n/a
Configuration 51
- < 1924
Running on/with
- n/a
Configuration 52
- < 1924
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15897 Advisory
- https://support.hp.com/in-en/document/c06428029 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15897 | Advisory | |
| https://support.hp.com/in-en/document/c06428029 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data