4.3

CVE-2012-3272

Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpColor Laserjet Cm3530 Version <= 53.190.8
HpColor Laserjet Cm60xx Version <= 53.190.8
HpColor Laserjet Cp3525 Version <= 06.140.3.17
HpColor Laserjet Cp4xxx Version <= 07.120.5
HpColor Laserjet Cp6015 Version <= 04.160.2
HpLaserjet P3015 Version <= 07.140.2
HpLaserjet P4xxx Version <= 04.170.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.676
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.