First published: Mon Jun 17 2019(Updated: )
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP T6B80A | <2019-04-19 | |
HP T6B80A Firmware | ||
HP T6b83a Firmware | <2019-04-19 | |
HP T6b83a Firmware | ||
HP T6B81A | <2019-04-19 | |
HP T6B81A Firmware | ||
HP T6B82A | <2019-04-19 | |
HP T6B82A Firmware | ||
HP W2G54A | <2019-04-26 | |
HP LaserJet Pro M14 | ||
HP W2G55A Firmware | <2019-04-26 | |
HP LaserJet Pro MFP M29 | ||
HP Y5s53a | <2019-04-26 | |
HP Y5s53a Firmware | ||
HP Y5s55a | <2019-04-26 | |
HP Y5s55a Firmware | ||
HP Y5s50a Firmware | <2019-04-26 | |
Hp Y5s50a Firmware | ||
HP Y5s54a Firmware | <2019-04-26 | |
HP Y5s54a Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6323 is classified as a medium risk due to the potential for reflected XSS attacks.
To fix CVE-2019-6323, upgrade the firmware of the affected HP printers to versions released after April 19, 2019.
The affected models include the HP Color LaserJet Pro M280-M281 and the HP LaserJet Pro MFP M28-M31 series printers.
Yes, the embedded web server vulnerability in CVE-2019-6323 can be exploited remotely via the wireless configuration page.
CVE-2019-6323 can facilitate reflected Cross-Site Scripting (XSS) attacks.