CVE-2021-3965

HIGHCVSS 7.5/10EPSS 5.24%

Last modified

CVE-2021-3965 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.. EPSS estimates a 5.24% chance of exploitation in the next 30 days.

Description

Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
5.24%

91.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpDesignjet T920 Cr355a Firmwaremry_07_07_04.1
HpDesignjet T920 Cr355b Firmwaremry_07_07_04.1
HpDesignjet T920 Cr354a Firmwaremry_07_07_04.1
HpDesignjet T930 L2y22a Firmwaremry_07_07_04.1
HpDesignjet T930 L2y22b Firmwaremry_07_07_04.1
HpDesignjet T930 L2y21a Firmwaremry_07_07_04.1
HpDesignjet T930 L2y21b Firmwaremry_07_07_04.1
HpDesignjet T1530 L2y24a Firmwaremry_07_07_04.1
HpDesignjet T1530 L2y24b Firmwaremry_07_07_04.1
HpDesignjet T1530 L2y23a Firmwaremry_07_07_04.1
HpDesignjet T2530 L2y25a Firmwaremry_07_07_04.1
HpDesignjet T2530 L2y26a Firmwaremry_07_07_04.1
HpDesignjet T2530 L2y26b Firmwaremry_07_07_04.1
HpDesignjet T3500 B9e24a Firmwareaeneas_04_09_06.1
HpDesignjet T3500 B9e24b Firmwareaeneas_04_09_06.1
HpDesignjet T3500 B9e25a Firmwareaeneas_04_09_06.1
HpDesignjet Z6800 F2s72a Firmwareptr8_03_07_06.1
HpDesignjet Z6800 F2s72ar Firmwareptr8_03_07_06.1
HpDesignjet Z6800 F2s72b Firmwareptr8_03_07_06.1
HpDesignjet Z6600 F2s71a Firmwareptr6_03_07_06.1
HpDesignjet Z6600 F2s71ar Firmwareptr6_03_07_06.1
HpDesignjet Z6810 2qu12a Firmwarepx8_06_05_02.1
HpDesignjet Z6810 2qu12b Firmwarepx8_06_05_02.1
HpDesignjet Z6810 2qu14a Firmwarepx8_06_05_02.1
HpDesignjet Z6810 2qu14b Firmwarepx8_06_05_02.1
HpDesignjet Z6610 2qu13b Firmwarepx6_06_05_02.1
HpDesignjet Z6610 2qu13a Firmwarepx6_06_05_02.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3965?
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.
How severe is CVE-2021-3965?
CVE-2021-3965 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 5.24% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3965?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3965?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST