PT-2012-4617 · Hewlett Packard · Hp Color Laserjet Cp3525+6
Published
2012-12-06
·
Updated
2013-01-08
·
CVE-2012-3272
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
HP Color LaserJet CM3530 versions prior to 53.190.9
HP Color LaserJet CM60xx versions prior to 52.210.9
HP Color LaserJet CP3525 versions prior to 06.140.3 18
HP Color LaserJet CP4xxx versions prior to 07.120.6
HP Color LaserJet CP6015 versions prior to 04.160.3
HP LaserJet P3015 versions prior to 07.140.3
HP LaserJet P4xxx versions prior to 04.170.3
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. This could potentially lead to unauthorized access or control of the affected devices.
Recommendations
For HP Color LaserJet CM3530, update the firmware to version 53.190.9 or later.
For HP Color LaserJet CM60xx, update the firmware to version 52.210.9 or later.
For HP Color LaserJet CP3525, update the firmware to version 06.140.3 18 or later.
For HP Color LaserJet CP4xxx, update the firmware to version 07.120.6 or later.
For HP Color LaserJet CP6015, update the firmware to version 04.160.3 or later.
For HP LaserJet P3015, update the firmware to version 07.140.3 or later.
For HP LaserJet P4xxx, update the firmware to version 04.170.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Color Laserjet Cm3530
Hp Color Laserjet Cm60Xx
Hp Color Laserjet Cp3525
Hp Color Laserjet Cp4Xxx
Hp Color Laserjet Cp6015
Hp Laserjet P3015
Hp Laserjet P4Xxx