7.5

CVE-2024-5749

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpF9a29a Firmware Version < 001.2419b
   HpF9a29a Version-
HpF9a29b Firmware Version < 001.2419b
   HpF9a29b Version-
HpF9a29c Firmware Version < 001.2419b
   HpF9a29c Version-
HpF9a29d Firmware Version < 001.2419b
   HpF9a29d Version-
HpF9a29e Firmware Version < 001.2419b
   HpF9a29e Version-
HpF9a29g Firmware Version < 001.2419b
   HpF9a29g Version-
HpT5d66a Firmware Version < 001.2419b
   HpT5d66a Version-
HpF9a30a Firmware Version < 001.2419b
   HpF9a30a Version-
HpF9a30b Firmware Version < 001.2419b
   HpF9a30b Version-
HpF9a30c Firmware Version < 001.2419b
   HpF9a30c Version-
HpF9a30d Firmware Version < 001.2419b
   HpF9a30d Version-
HpF9a30e Firmware Version < 001.2419b
   HpF9a30e Version-
HpF9a30g Firmware Version < 001.2419b
   HpF9a30g Version-
Hp1jl02b Firmware Version < 001.2419b
   Hp1jl02b Version-
HpT5d67a Firmware Version < 001.2419b
   HpT5d67a Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.364
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
hp-security-alert@hp.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.