CVE-2019-6325: CSRF
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6325?
The severity of CVE-2019-6325 is categorized as medium, primarily due to the Cross-site Request Forgery vulnerability.
How do I fix CVE-2019-6325?
To fix CVE-2019-6325, update the firmware of the affected HP printers to versions released after April 19, 2019 for T6B80A, T6B83A, T6B81A, T6B82A, and after April 26, 2019 for W2G54A, W2G55A, Y5S53A, Y5S55A, Y5S50A, and Y5S54A.
Which HP printers are affected by CVE-2019-6325?
CVE-2019-6325 affects HP Color LaserJet Pro M280-M281 and HP LaserJet Pro MFP M28-M31 Multifunction Printer series with firmware versions prior to specific release dates.
What kind of attack is CVE-2019-6325 associated with?
CVE-2019-6325 is associated with Cross-site Request Forgery attacks, which could lead to unauthorized actions performed on behalf of a user.
Is CVE-2019-6325 a persistent vulnerability?
CVE-2019-6325 is not persistent since it is resolved through a firmware update that eliminates the vulnerability.