CVE-2019-6332

moderate-risk
Published 2020-01-09

A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink Advantage 2600 All-in-One Printer series model numbers V1N02A - V1N02B, Y5Z00A - Y5Z04B; HP DeskJet Ink Advantage 5000 All-in-One Printer series model numbers M2U86A - M2U89B; HP DeskJet Ink Advantage 5200 All-in-One Printer series model numbers M2U76A - M2U78B; HP ENVY 5000 All-in-One Printer series model numbers M2U85A - M2U85B, M2U91A - M2U94B, Z4A54A - Z4A74A; HP ENVY Photo 6200 All-in-One Printer series model numbers K7G18A-K7G26B, K7S21B, Y0K13D - Y0K15A; HP ENVY Photo 7100 All-in-One Printer series model numbers 3XD89A, K7G93A-K7G99A, Z3M37A - Z3M52A; HP ENVY Photo 7800 All-in-One Printer series model numbers K7R96A, K7S00A - K7S10D, Y0G42D - Y0G52B; HP Ink Tank Wireless 410 series model numbers Z4B53A - Z4B55A, Z6Z95A - Z6Z99A, 4DX94A - 4DX95A, 4YF79A, Z7A01A; HP OfficeJet 5200 All-in-One Printer series model numbers M2U75A, M2U81A-M2U84B, Z4B12A - Z4B14A, Z4B27A - Z4B29A; HP Smart Tank Wireless 450 series model numbers Z4B56A, Z6Z96A - Z6Z98A.

Do I need to act?

-
0.29% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.8/10 Medium
NETWORK / LOW complexity

Affected Products (20)

Deskjet 2600 4Uj28B Firmware
Deskjet 2600 V1N01A Firmware
Deskjet 2600 V1N08A Firmware
Deskjet 2600 Y5H60A Firmware
Deskjet 2600 Y5H80A Firmware
Deskjet Ink Advantage 2600 V1N02A Firmware
Deskjet Ink Advantage 2600 V1N02B Firmware
Deskjet Ink Advantage 2600 Y5Z00A Firmware
Deskjet Ink Advantage 2600 Y5Z04B Firmware
Deskjet Ink Advantage 5000 M2U86A Firmware
Deskjet Ink Advantage 5000 M2U89B Firmware
Deskjet Ink Advantage 5200 M2U76A Firmware
Deskjet Ink Advantage 5200 M2U78B Firmware
Envy 5000 M2U85A Firmware
Envy 5000 M2U85B Firmware
Envy 5000 M2U91A Firmware
Envy 5000 M2U94B Firmware
Envy 5000 Z4A54A Firmware
Envy 5000 Z4A74A Firmware
Envy Photo 6200 K7G18A Firmware

Affected Vendors

Hp
46
/ 100
moderate-risk
Severity 19/34 · Moderate
Exploitability 1/34 · Minimal
Exposure 26/34 · High