CVE-2019-18914
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
09/11/2021
Last modified:
15/11/2021
Description
A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* | 2309025_582081 (excluding) | |
| cpe:2.3:h:hp:laserjet_cm4540_mfp_cc419a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_cm4540_mfp_cc420a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_cm4540_mfp_cc421a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:futuresmart_3:*:*:*:*:*:*:*:* | 2309025_582098 (excluding) | |
| cpe:2.3:o:hp:futuresmart_4:*:*:*:*:*:*:*:* | 2410028_055010 (excluding) | |
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_a2w75a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_a2w76a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_d7p70a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_d7p71a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_l3u51a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_enterprise_flow_mfp_m880z_l3u52a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_a2w75a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_a2w76a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:laserjet_managed_flow_mfp_m880zm_d7p70a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



