CVE-2017-2743
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
23/01/2018
Last modified:
13/02/2018
Description
HP has identified a potential security vulnerability with HP Enterprise LaserJet Printers and MFPs, HP OfficeJet Enterprise Color Printers and MFP, HP PageWide Color Printers and MPS before 2308214_000901, 2308214_000900, and other firmware versions. The vulnerability could be exploited to perform a cross site scripting (XSS) attack.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:hp:cc419a_firmware:*:*:*:*:*:*:*:* | 2308214_000901 (excluding) | |
cpe:2.3:h:hp:cc419a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:cc420a_firmware:*:*:*:*:*:*:*:* | 2308214_000901 (excluding) | |
cpe:2.3:h:hp:cc420a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:cc421a_firmware:*:*:*:*:*:*:*:* | 2308214_000901 (excluding) | |
cpe:2.3:h:hp:cc421a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:ce709a_firmware:*:*:*:*:*:*:*:* | 2308214_000900 (excluding) | |
cpe:2.3:h:hp:ce709a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:ce708a_firmware:*:*:*:*:*:*:*:* | 2308214_000900 (excluding) | |
cpe:2.3:h:hp:ce708a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:ce707a_firmware:*:*:*:*:*:*:*:* | 2308214_000900 (excluding) | |
cpe:2.3:h:hp:ce707a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:ce503a_firmware:*:*:*:*:*:*:*:* | 2308214_000904 (excluding) | |
cpe:2.3:h:hp:ce503a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:hp:ce504a_firmware:*:*:*:*:*:*:*:* | 2308214_000904 (excluding) |
To consult the complete list of CPE names with products and versions, see this page