Lucene search

K
cveMitreCVE-2022-48311
HistoryFeb 06, 2023 - 9:15 p.m.

CVE-2022-48311

2023-02-0621:15:09
CWE-79
mitre
web.nvd.nist.gov
31
xss
cross site scripting
hp deskjet
printer
firmware
security vulnerability
cve-2022-48311

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

42.4%

UNSUPPORTED WHEN ASSIGNED Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected configurations

Nvd
Node
hpdeskjet_2540_a9u23bMatch-
AND
hpdeskjet_2540_a9u23b_firmwareMatchcep1fn1418br
VendorProductVersionCPE
hpdeskjet_2540_a9u23b-cpe:2.3:h:hp:deskjet_2540_a9u23b:-:*:*:*:*:*:*:*
hpdeskjet_2540_a9u23b_firmwarecep1fn1418brcpe:2.3:o:hp:deskjet_2540_a9u23b_firmware:cep1fn1418br:*:*:*:*:*:*:*

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

42.4%

Related for CVE-2022-48311