6.9
CVE-2026-1997
- EPSS 0.01%
- Veröffentlicht 10.02.2026 18:16:22
- Zuletzt bearbeitet 12.02.2026 15:13:31
- Quelle hp-security-alert@hp.com
- CVE-Watchlists
- Unerledigt
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ M9l65a Firmware Version < 001.2602a
Hp ≫ D9l20a Firmware Version < 001.2602b
Hp ≫ K7s32a Firmware Version < 001.2602b
Hp ≫ D9l21a Firmware Version < 001.2602b
Hp ≫ K7s42a Firmware Version < 001.2602b
Hp ≫ T0g65a Firmware Version < 001.2602b
Hp ≫ K7s39a Firmware Version < 001.2602b
Hp ≫ J6x83a Firmware Version < 001.2602b
Hp ≫ K7s43a Firmware Version < 001.2602b
Hp ≫ K7s40a Firmware Version < 001.2602b
Hp ≫ K7s41a Firmware Version < 001.2602b
Hp ≫ T0g56a Firmware Version < 001.2602b
Hp ≫ D9l63a Firmware Version < 001.2602b
Hp ≫ D9l64a Firmware Version < 001.2602b
Hp ≫ J3p65a Firmware Version < 001.2602b
Hp ≫ J3p66a Firmware Version < 001.2602b
Hp ≫ J3p67a Firmware Version < 001.2602b
Hp ≫ J3p68a Firmware Version < 001.2602b
Hp ≫ T0g70a Firmware Version < 001.2602b
Hp ≫ G5j38a Firmware Version < 001.2602a
Hp ≫ T1p99a Firmware Version < 001.2602a
Hp ≫ L3t99a Firmware Version < 001.2602a
Hp ≫ Y0s19a Firmware Version < 001.2602a
Hp ≫ G5j56a Firmware Version < 001.2602a
Hp ≫ Y0s18a Firmware Version < 001.2602a
Hp ≫ D9l18a Firmware Version < 001.2602a
Hp ≫ M9l66a Firmware Version < 001.2602a
Hp ≫ M9l67a Firmware Version < 001.2602a
Hp ≫ T0g46a Firmware Version < 001.2602a
Hp ≫ J6x76a Firmware Version < 001.2602a
Hp ≫ J6x78a Firmware Version < 001.2602a
Hp ≫ J6x80a Firmware Version < 001.2602a
Hp ≫ K7s37a Firmware Version < 001.2602a
Hp ≫ M9l70a Firmware Version < 001.2602a
Hp ≫ J6x77a Firmware Version < 001.2602a
Hp ≫ J6x81a Firmware Version < 001.2602a
Hp ≫ J6x79a Firmware Version < 001.2602a
Hp ≫ K7s38a Firmware Version < 001.2602a
Hp ≫ T0g47a Firmware Version < 001.2602a
Hp ≫ T0g48a Firmware Version < 001.2602a
Hp ≫ T0g49a Firmware Version < 001.2602a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.002 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| hp-security-alert@hp.com | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.