CVE-2012-3272
Last modified
CVE-2012-3272 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet Cm3530 | <= 53.190.8 |
| Hp | Color Laserjet Cm60xx | <= 53.190.8 |
| Hp | Color Laserjet Cp3525 | <= 06.140.3.17 |
| Hp | Color Laserjet Cp4xxx | <= 07.120.5 |
| Hp | Color Laserjet Cp6015 | <= 04.160.2 |
| Hp | Laserjet P3015 | <= 07.140.2 |
| Hp | Laserjet P4xxx | <= 04.170.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3272?
How severe is CVE-2012-3272?
How do I fix CVE-2012-3272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-3266Unspecified vulnerability in IBRIX 6.1.196 through 6.1.251 o…
- CVE-2012-3267Unspecified vulnerability in HP Network Node Manager i (NNMi…
- CVE-2012-3268Certain HP Access Controller, Fabric Module, Firewall, Route…
- CVE-2012-3269Unspecified vulnerability in HP Performance Insight 5.31, 5.…
- CVE-2012-3270Unspecified vulnerability in HP Performance Insight 5.31, 5.…
- CVE-2012-3271Unspecified vulnerability on the HP Integrated Lights-Out 3 …
- CVE-2012-3273Multiple unspecified vulnerabilities on the HP LaserJet Pro …
- CVE-2012-3274Stack-based buffer overflow in uam.exe in the User Access Ma…
- CVE-2012-3275Unspecified vulnerability in HP Network Node Manager i (NNMi…
- CVE-2012-3276HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and…
- CVE-2012-3277HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and…
- CVE-2012-3278Stack-based buffer overflow in magentservice.exe in HP Diagn…
Are you affected by CVE-2012-3272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
