CVE-2019-6324

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to stored XSS in wireless configuration page
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:t6b80a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t6b80a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hp:t6b83a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t6b83a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hp:t6b81a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t6b81a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hp:t6b82a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:t6b82a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hp:w2g54a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w2g54a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hp:w2g55a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w2g55a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hp:y5s53a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y5s53a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hp:y5s55a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y5s55a:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hp:y5s50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y5s50a:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hp:y5s54a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:y5s54a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:46

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/c06356322 - Vendor Advisory () https://support.hp.com/us-en/document/c06356322 - Vendor Advisory

Information

Published : 2019-06-17 16:15

Updated : 2024-11-21 04:46


NVD link : CVE-2019-6324

Mitre link : CVE-2019-6324

CVE.ORG link : CVE-2019-6324


JSON object : View

Products Affected

hp

  • t6b80a
  • y5s55a
  • t6b82a
  • t6b81a
  • t6b80a_firmware
  • y5s53a_firmware
  • w2g54a
  • y5s53a
  • t6b82a_firmware
  • t6b83a
  • y5s55a_firmware
  • w2g55a
  • t6b81a_firmware
  • y5s54a
  • w2g54a_firmware
  • w2g55a_firmware
  • y5s54a_firmware
  • y5s50a_firmware
  • y5s50a
  • t6b83a_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')