6.3
CVE-2024-2209
- EPSS 0.07%
- Veröffentlicht 27.03.2024 00:15:07
- Zuletzt bearbeitet 20.02.2026 21:15:05
- Quelle hp-security-alert@hp.com
- CVE-Watchlists
- Unerledigt
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ 26k70b Firmware Version < 2349b
Hp ≫ 297x1a Firmware Version < 2349b
Hp ≫ 2a9q5a Firmware Version < 2349b
Hp ≫ 26k72a Firmware Version < 2349b
Hp ≫ 26k69a Firmware Version < 2349b
Hp ≫ 26k70a Firmware Version < 2349b
Hp ≫ 26k71a Firmware Version < 2349b
Hp ≫ 26k68a Firmware Version < 2349b
Hp ≫ 26k67a Firmware Version < 2349b
Hp ≫ 3xv19a Firmware Version < 2349b
Hp ≫ 7fr52a Firmware Version < 2349b
Hp ≫ 7fr57a Firmware Version < 2349b
Hp ≫ 7fr53a Firmware Version < 2349b
Hp ≫ 7fr58a Firmware Version < 2349b
Hp ≫ 7fr61a Firmware Version < 2349b
Hp ≫ 5ar83a Firmware Version < 2349b
Hp ≫ 5ar84a Firmware Version < 2349b
Hp ≫ 5ar85a Firmware Version < 2349b
Hp ≫ 8rk11a Firmware Version < 2349b
Hp ≫ 3xv17a Firmware Version < 2349b
Hp ≫ 4ws04a Firmware Version < 2349b
Hp ≫ 7fr21a Firmware Version < 2349b
Hp ≫ 7fr20a Firmware Version < 2349b
Hp ≫ 26k72b Firmware Version < 2349c
Hp ≫ 26k67b Firmware Version < 2349c
Hp ≫ 297w8a Firmware Version < 2349c
Hp ≫ 26k68b Firmware Version < 2349c
Hp ≫ 297x0a Firmware Version < 2349c
Hp ≫ 26k70b Firmware Version < 2349c
Hp ≫ 297x1a Firmware Version < 2349c
Hp ≫ 2a9q5a Firmware Version < 2349c
Hp ≫ 26k72a Firmware Version < 2349c
Hp ≫ 26k69a Firmware Version < 2349c
Hp ≫ 26k70a Firmware Version < 2349c
Hp ≫ 26k71a Firmware Version < 2349c
Hp ≫ 26k68a Firmware Version < 2349c
Hp ≫ 26k67a Firmware Version < 2349c
Hp ≫ 3xv19a Firmware Version < 2349c
Hp ≫ 7fr52a Firmware Version < 2349c
Hp ≫ 7fr57a Firmware Version < 2349c
Hp ≫ 26k72b Firmware Version < 2349b
Hp ≫ 26k67b Firmware Version < 2349b
Hp ≫ 297w8a Firmware Version < 2349b
Hp ≫ 26k68b Firmware Version < 2349b
Hp ≫ 297x0a Firmware Version < 2349b
Hp ≫ 7fr53a Firmware Version < 2349c
Hp ≫ 7fr58a Firmware Version < 2349c
Hp ≫ 7fr61a Firmware Version < 2349c
Hp ≫ 5ar83a Firmware Version < 2349c
Hp ≫ 5ar84a Firmware Version < 2349c
Hp ≫ 5ar85a Firmware Version < 2349c
Hp ≫ 8rk11a Firmware Version < 2349c
Hp ≫ 3xv17a Firmware Version < 2349c
Hp ≫ 4ws04a Firmware Version < 2349c
Hp ≫ 7fr21a Firmware Version < 2349c
Hp ≫ 7fr20a Firmware Version < 2349c
Hp ≫ 7fr21a Firmware Version < 2349d
Hp ≫ 26k72b Firmware Version < 2349d
Hp ≫ 26k67b Firmware Version < 2349d
Hp ≫ 297w8a Firmware Version < 2349d
Hp ≫ 26k68b Firmware Version < 2349d
Hp ≫ 297x0a Firmware Version < 2349d
Hp ≫ 26k70b Firmware Version < 2349d
Hp ≫ 297x1a Firmware Version < 2349d
Hp ≫ 2a9q5a Firmware Version < 2349d
Hp ≫ 26k72a Firmware Version < 2349d
Hp ≫ 26k69a Firmware Version < 2349d
Hp ≫ 26k70a Firmware Version < 2349d
Hp ≫ 26k71a Firmware Version < 2349d
Hp ≫ 26k68a Firmware Version < 2349d
Hp ≫ 26k67a Firmware Version < 2349d
Hp ≫ 3xv19a Firmware Version < 2349d
Hp ≫ 7fr52a Firmware Version < 2349d
Hp ≫ 7fr57a Firmware Version < 2349d
Hp ≫ 7fr53a Firmware Version < 2349d
Hp ≫ 7fr58a Firmware Version < 2349d
Hp ≫ 7fr61a Firmware Version < 2349d
Hp ≫ 5ar83a Firmware Version < 2349d
Hp ≫ 5ar84a Firmware Version < 2349d
Hp ≫ 5ar85a Firmware Version < 2349d
Hp ≫ 8rk11a Firmware Version < 2349d
Hp ≫ 3xv17a Firmware Version < 2349d
Hp ≫ 4ws04a Firmware Version < 2349d
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.201 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.3 | 0.8 | 5.5 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.