CVE-2018-5921

UnknownEPSS 0.74%

Last modified

CVE-2018-5921 is a vulnerability of currently unknown severity. A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.

Description

A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.

Metrics

EPSS Probability
0.74%

49.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpF2a70a Firmware< 2405129_000052
HpF2a71a Firmware< 2405129_000052
HpF2a67a Firmware< 2405129_000052
HpB5l26a Firmware< 2405129_000056
HpB5l39a Firmware< 2405129_000056
HpC2s11a Firmware< 2405129_000055
HpC2s11v Firmware< 2405129_000055
HpC2s12a Firmware< 2405129_000055
HpC2s12v Firmware< 2405129_000055
HpL1h45a Firmware< 2405129_000055
HpG1w46a Firmware< 2405129_000051
HpG1w46v Firmware< 2405129_000051
HpG1w47a Firmware< 2405129_000051
HpG1w47v Firmware< 2405129_000051
HpL3u44a Firmware< 2405129_000051
HpL3u44a Firmware< 2405135_000394
HpE6b71a Firmware< 2405129_000046
HpE6b73a Firmware< 2405129_000046
HpK0q14a Firmware< 2405130_000069
HpK0q15a Firmware< 2405130_000069
HpK0q17a Firmware< 2405130_000069
HpK0q18a Firmware< 2405130_000069
HpM0p32a Firmware< 2405130_000069
HpK0q19a Firmware< 2405130_000069
HpK0q20a Firmware< 2405130_000069
HpK0q21a Firmware< 2405130_000069
HpK0q22a Firmware< 2405130_000069
HpM0p33a Firmware< 2405130_000069
HpM0p35a Firmware< 2405130_000069
HpM0p36a Firmware< 2405130_000069
HpM0p39a Firmware< 2405130_000069
HpM0p40a Firmware< 2405130_000069
HpH0dc9a Firmware< 2405129_000047
HpL8z07a Firmware< 2405129_000047
HpJ7z98a Firmware< 2405130_000068
HpJ7z99a Firmware< 2405130_000068
HpJ8a04a Firmware< 2405130_000068
HpJ8a05a Firmware< 2405130_000068
HpJ8a06a Firmware< 2405130_000068
HpL3u55a Firmware< 2405130_000068
HpL3u56a Firmware< 2405130_000068
HpL3u57a Firmware< 2405130_000068
HpJ7z04a Firmware< 2405087_018564
HpJ7z06a Firmware< 2405087_018564
HpCz244a Firmware< 2405129_000059
HpA2w77a Firmware< 2405129_000057
HpCz245a Firmware< 2405129_000059
HpA2w78a Firmware< 2405129_000057
HpA2w79a Firmware< 2405129_000057
HpD7p73a Firmware< 2405129_000057

Showing 50 of 197 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-5921?
A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.
How severe is CVE-2018-5921?
Severity scoring for CVE-2018-5921 is pending analysis. The EPSS model estimates a 0.74% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5921?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-5921?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST