Lucene search

K
cveMitreCVE-2009-2684
HistoryOct 13, 2009 - 10:30 a.m.

CVE-2009-2684

2009-10-1310:30:00
CWE-79
mitre
web.nvd.nist.gov
40
cve-2009-2684
xss
hp printers
digital senders
security vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.005

Percentile

75.7%

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

Affected configurations

Nvd
Node
hpcm8050_mfp
OR
hpcm8060_mfp
OR
hpcolor_laserjet_3000n
OR
hpcolor_laserjet_3600n
OR
hpcolor_laserjet_3800n
OR
hpcolor_laserjet_4700n
OR
hpcolor_laserjet_4730_mfp
OR
hpcolor_laserjet_6040_mfp
OR
hpcolor_laserjet_cm4730_mfp
OR
hpcolor_laserjet_cp3505
OR
hpcolor_laserjet_cp4005n
OR
hpcolor_laserjet_cp6015
OR
hpds_9200c
OR
hpds_9250c
OR
hplaserjet_2410
OR
hplaserjet_2420
OR
hplaserjet_2430n
OR
hplaserjet_4240
OR
hplaserjet_4250n
OR
hplaserjet_4345_mfp
OR
hplaserjet_4350n
OR
hplaserjet_5200n
OR
hplaserjet_9040_mfp
OR
hplaserjet_9040n
OR
hplaserjet_9050_mfp
OR
hplaserjet_9050n
OR
hplaserjet_m3027_mfp
OR
hplaserjet_m3035_mfp
OR
hplaserjet_m4345x_mfp
OR
hplaserjet_m5025_mfp
OR
hplaserjet_m9040_mpf
OR
hplaserjet_m9050_mpf
OR
hplaserjet_p3005n
OR
hplaserjet_p4014
OR
hplaserjet_p4515
VendorProductVersionCPE
hpcm8050_mfp*cpe:2.3:h:hp:cm8050_mfp:*:*:*:*:*:*:*:*
hpcm8060_mfp*cpe:2.3:h:hp:cm8060_mfp:*:*:*:*:*:*:*:*
hpcolor_laserjet_3000n*cpe:2.3:h:hp:color_laserjet_3000n:*:*:*:*:*:*:*:*
hpcolor_laserjet_3600n*cpe:2.3:h:hp:color_laserjet_3600n:*:*:*:*:*:*:*:*
hpcolor_laserjet_3800n*cpe:2.3:h:hp:color_laserjet_3800n:*:*:*:*:*:*:*:*
hpcolor_laserjet_4700n*cpe:2.3:h:hp:color_laserjet_4700n:*:*:*:*:*:*:*:*
hpcolor_laserjet_4730_mfp*cpe:2.3:h:hp:color_laserjet_4730_mfp:*:*:*:*:*:*:*:*
hpcolor_laserjet_6040_mfp*cpe:2.3:h:hp:color_laserjet_6040_mfp:*:*:*:*:*:*:*:*
hpcolor_laserjet_cm4730_mfp*cpe:2.3:h:hp:color_laserjet_cm4730_mfp:*:*:*:*:*:*:*:*
hpcolor_laserjet_cp3505*cpe:2.3:h:hp:color_laserjet_cp3505:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.005

Percentile

75.7%