CVE-2024-5749: Certain HP DesignJet products – Credential reflection

Published Oct 15, 2024
·
Updated

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

Affected Software

30 affected components
All of the following
HP F9a29a Firmware<001.2419b
HP F9a29a
All of the following
HP F9a29b Firmware<001.2419b
HP F9a29b
All of the following
HP F9a29c Firmware<001.2419b
HP F9a29c
All of the following
HP F9a29d Firmware<001.2419b
HP F9a29d
All of the following
HP F9a29e Firmware<001.2419b
HP F9a29e
All of the following
HP F9a29g Firmware<001.2419b
HP F9a29g
All of the following
HP T5d66a Firmware<001.2419b
HP T5d66a
All of the following
HP F9a30a Firmware<001.2419b
HP F9a30a
All of the following
HP F9a30b Firmware<001.2419b
HP F9a30b
All of the following
HP F9a30c Firmware<001.2419b
HP F9a30c
All of the following
HP F9a30d Firmware<001.2419b
HP F9a30d
All of the following
HP F9a30e Firmware<001.2419b
HP F9a30e
All of the following
HP F9a30g Firmware<001.2419b
HP F9a30g
All of the following
HP 1jl02b Firmware<001.2419b
HP 1jl02b
All of the following
HP T5d67a Firmware<001.2419b
HP T5d67a

Event History

Oct 15, 2024
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-5749?

The severity of CVE-2024-5749 is critical due to the potential exposure of SMTP server credentials.

2

How do I fix CVE-2024-5749?

To fix CVE-2024-5749, update the firmware of your affected HP DesignJet products to the latest version beyond 001.2419b.

3

Which HP DesignJet products are affected by CVE-2024-5749?

Affected products include HP F9a29a, F9a29b, F9a29c, F9a29d, F9a29e, F9a29g, T5d66a, F9a30a to F9a30g, and others running firmware up to 001.2419b.

4

What is credential reflection vulnerability in CVE-2024-5749?

Credential reflection vulnerability in CVE-2024-5749 allows unauthorized users to view SMTP server credentials used by the printer.

5

Can I prevent CVE-2024-5749 without a firmware update?

No, the only way to effectively mitigate CVE-2024-5749 is by applying the necessary firmware updates to your devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203