CVE-2019-6323: XSS
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server potentially vulnerable to reflected XSS in wireless configuration page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6323?
The severity of CVE-2019-6323 is classified as a medium risk due to the potential for reflected XSS attacks.
How do I fix CVE-2019-6323?
To fix CVE-2019-6323, upgrade the firmware of the affected HP printers to versions released after April 19, 2019.
What HP printer models are affected by CVE-2019-6323?
The affected models include the HP Color LaserJet Pro M280-M281 and the HP LaserJet Pro MFP M28-M31 series printers.
Is the web server vulnerability of CVE-2019-6323 remotely exploitable?
Yes, the embedded web server vulnerability in CVE-2019-6323 can be exploited remotely via the wireless configuration page.
What type of attacks can CVE-2019-6323 facilitate?
CVE-2019-6323 can facilitate reflected Cross-Site Scripting (XSS) attacks.