9.1

CVE-2019-16240

A Buffer Overflow and Information Disclosure issue exists in HP OfficeJet Pro Printers before 001.1937C, and HP PageWide Managed Printers and HP PageWide Pro Printers before 001.1937D exists; A maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

Data is provided by the National Vulnerability Database (NVD)
HpPagewide Pro 577z K9z76a Firmware Version < 001.1937d
   HpPagewide Pro 577z K9z76a Version-
HpPagewide Pro 577z K9z76b Firmware Version < 001.1937d
   HpPagewide Pro 577z K9z76b Version-
HpPagewide Pro 577z K9z76d Firmware Version < 001.1937d
   HpPagewide Pro 577z K9z76d Version-
HpPagewide Pro 577dw D3q21a Firmware Version < 001.1937d
   HpPagewide Pro 577dw D3q21a Version-
HpPagewide Pro 577dw D3q21b Firmware Version < 001.1937d
   HpPagewide Pro 577dw D3q21b Version-
HpPagewide Pro 577dw D3q21c Firmware Version < 001.1937d
   HpPagewide Pro 577dw D3q21c Version-
HpPagewide Pro 577dw D3q21d Firmware Version < 001.1937d
   HpPagewide Pro 577dw D3q21d Version-
HpPagewide Pro 552dw 2dr21d Firmware Version < 001.1937d
   HpPagewide Pro 552dw 2dr21d Version-
HpPagewide Pro 552dw D3q17a Firmware Version < 001.1937d
   HpPagewide Pro 552dw D3q17a Version-
HpPagewide Pro 552dw D3q17d Firmware Version < 001.1937d
   HpPagewide Pro 552dw D3q17d Version-
HpPagewide Pro 552dw K9z74a Firmware Version < 001.1937d
   HpPagewide Pro 552dw K9z74a Version-
HpPagewide Pro 552dw K9z74d Firmware Version < 001.1937d
   HpPagewide Pro 552dw K9z74d Version-
HpPagewide Pro 477dw D3q20a Firmware Version < 001.1937d
   HpPagewide Pro 477dw D3q20a Version-
HpPagewide Pro 477dw D3q20b Firmware Version < 001.1937d
   HpPagewide Pro 477dw D3q20b Version-
HpPagewide Pro 477dw D3q20c Firmware Version < 001.1937d
   HpPagewide Pro 477dw D3q20c Version-
HpPagewide Pro 477dw D3q20d Firmware Version < 001.1937d
   HpPagewide Pro 477dw D3q20d Version-
HpPagewide Pro 477dw W2z53b Firmware Version < 001.1937d
   HpPagewide Pro 477dw W2z53b Version-
HpPagewide Pro 477dn D3q19d Firmware Version < 001.1937d
   HpPagewide Pro 477dn D3q19d Version-
HpPagewide Pro 477dn D3q19b Firmware Version < 001.1937d
   HpPagewide Pro 477dn D3q19b Version-
HpPagewide Pro 477dn D3q19a Firmware Version < 001.1937d
   HpPagewide Pro 477dn D3q19a Version-
HpPagewide Pro 452dw W2z52b Firmware Version < 001.1937d
   HpPagewide Pro 452dw W2z52b Version-
HpPagewide Pro 452dw D3q16d Firmware Version < 001.1937d
   HpPagewide Pro 452dw D3q16d Version-
HpPagewide Pro 452dw D3q16a Firmware Version < 001.1937d
   HpPagewide Pro 452dw D3q16a Version-
HpPagewide Pro 452dn D3q15d Firmware Version < 001.1937d
   HpPagewide Pro 452dn D3q15d Version-
HpPagewide Pro 452dn D3q15b Firmware Version < 001.1937d
   HpPagewide Pro 452dn D3q15b Version-
HpPagewide Pro 452dn D3q15a Firmware Version < 001.1937d
   HpPagewide Pro 452dn D3q15a Version-
HpPagewide 377dw J9v80b Firmware Version < 001.1937d
   HpPagewide 377dw J9v80b Version-
HpPagewide 377dw J9v80a Firmware Version < 001.1937d
   HpPagewide 377dw J9v80a Version-
HpPagewide 352dw J6u57b Firmware Version < 001.1937d
   HpPagewide 352dw J6u57b Version-
HpPagewide 352dw J6u57a Firmware Version < 001.1937d
   HpPagewide 352dw J6u57a Version-
HpOfficejet Pro 8210 D9l63a Firmware Version < 001.1937c
   HpOfficejet Pro 8210 D9l63a Version-
HpOfficejet Pro 8210 D9l64a Firmware Version < 001.1937c
   HpOfficejet Pro 8210 D9l64a Version-
HpOfficejet Pro 8210 J3p65a Firmware Version < 001.1937c
   HpOfficejet Pro 8210 J3p65a Version-
HpOfficejet Pro 8210 J3p68a Firmware Version < 001.1937c
   HpOfficejet Pro 8210 J3p68a Version-
HpOfficejet Pro 8210 T0g70a Firmware Version < 001.1937c
   HpOfficejet Pro 8210 T0g70a Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.92% 0.751
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.