CVE-2021-3942
Last modified
CVE-2021-3942 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet Cm4540 Mfp Cc419a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm4540 Mfp Cc420a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm4540 Mfp Cc421a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce707a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce708a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce709a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet M578 Mfp 7zu85a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7zu85a Firmware | >= 5.0, < 5.4 |
| Hp | Color Laserjet M578 Mfp 7zu86a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7zu86a Firmware | >= 5.0.0, < 5.4 |
| Hp | Color Laserjet M578 Mfp 7zu87a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7zu87a Firmware | >= 5.0.0, < 5.4 |
| Hp | Color Laserjet M578 Mfp 7zu88a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7zu88a Firmware | >= 5.0.0, < 5.4 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z D7p70a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z D7p70a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z A2w75a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z A2w75a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z A2w76a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z A2w76a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z D7p71a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z D7p71a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z L3u51a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z L3u51a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z L3u52a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise Flow Mfp M880z L3u52a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm D7p70a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm D7p70a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm A2w75a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm A2w75a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm A2w76a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm A2w76a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm D7p71a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm D7p71a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm L3u51a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm L3u51a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Managed Flow Mfp M880zm L3u52a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Managed Flow Mfp M880zm L3u52a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M455 39z95a Firmware | >= 5.0, < 5.4 |
| Hp | Color Laserjet M552 B5l23a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet M552 B5l23a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M552 B5l23a Firmware | >= 5.0, < 5.4 |
| Hp | Color Laserjet Enterprise M553 B5l24a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise M553 B5l24a Firmware | >= 4.0, < 4.11.23 |
| Hp | Color Laserjet Enterprise M553 B5l24a Firmware | >= 5.0, < 5.4 |
| Hp | Color Laserjet Enterprise M553 B5l25a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise M553 B5l25a Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet Enterprise M553 B5l25a Firmware | >= 5.0, < 5.4 |
| Hp | Color Laserjet Enterprise M553 B5l26a Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Enterprise M553 B5l26a Firmware | >= 4.0, < 4.11.2.3 |
Showing 50 of 2783 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3942?
How severe is CVE-2021-3942?
How do I fix CVE-2021-3942?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-39409A vulnerability exists in Online Student Rate System v1.0 th…9.8
- CVE-2021-3941In ImfChromaticities.cpp routine RGBtoXYZ(), there are some …6.5
- CVE-2021-39411Multiple Cross Site Scripting (XSS) vulnerabilities exist in…6.1
- CVE-2021-39412Multiple Cross Site Scripting (XSS) vulnerabilities exists i…6.1
- CVE-2021-39413Multiple Cross Site Scripting (XSS) vulnerabilities exits in…6.1
- CVE-2021-39416Multiple Cross Site Scripting (XSS) vulnerabilities exists i…6.1
- CVE-2021-39420Multiple Cross Site Scripting (XSS) vulnerabilities exist in…6.1
- CVE-2021-39421A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.1…6.1
- CVE-2021-39425SeedDMS v6.0.15 was discovered to contain an open redirect v…6.1
- CVE-2021-39426An issue was discovered in /Upload/admin/admin_notify.php in…9.8
- CVE-2021-39427Cross site scripting vulnerability in 188Jianzhan 2.10 allow…5.4
- CVE-2021-39428Cross Site Scripting (XSS) vulnerability in Users.php in eyo…5.4
Are you affected by CVE-2021-3942?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
