CVE-2024-0407

MEDIUMCVSS 6.5/10EPSS 0.34%

Last modified

CVE-2024-0407 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.

Description

Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

EPSS Probability
0.34%

25.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HpFuturesmart 4< 2411265_067635
HpFuturesmart 4< 2411265_067634
HpFuturesmart 4< 2411265_067627
HpFuturesmart 4< 2411265_067630
HpFuturesmart 4< 2411265_067628
HpFuturesmart 4< 2411265_067632
HpFuturesmart 4All versions
HpFuturesmart 3< 2309110_002023
HpFuturesmart 3< 2309110_002029
HpFuturesmart 3< 2309110_002016
HpFuturesmart 3< 2309110_002022
HpFuturesmart 5< 2507252_046145
HpFuturesmart 5< 2507252_046159
HpFuturesmart 5< 2507252_046129
HpFuturesmart 5< 2507252_046112
HpFuturesmart 5< 2507252_046140
HpFuturesmart 5< 2507252_046117
HpFuturesmart 5< 2507252_046111
HpFuturesmart 5< 2507252_046144
HpFuturesmart 5< 2507252_046153
HpFuturesmart 5< 2507252_046166
HpFuturesmart 5< 2507252_046130
HpFuturesmart 5< 2507252_046160
HpFuturesmart 5< 2507252_046127
HpFuturesmart 5< 2507252_046167
HpFuturesmart 5< 2507252_046165
HpFuturesmart 5< 2507252_046168
HpFuturesmart 5< 2507252_046154
HpFuturesmart 3< 2309110_002028
HpFuturesmart 5< 2507252_046136
HpFuturesmart 5< 2507252_046123
HpFuturesmart 5< 2507252_046161
HpFuturesmart 5< 2507252_046158
HpFuturesmart 5< 2507252_046147
HpFuturesmart 5< 2507252_046139
HpFuturesmart 5< 2507252_046115
HpFuturesmart 5< 2507252_046124
HpFuturesmart 5< 2507252_046110
HpFuturesmart 5< 2507252_046142
HpFuturesmart 5< 2507252_046132
HpFuturesmart 5< 2507252_046155
HpFuturesmart 5< 2507252_046137
HpFuturesmart 5< 2507252_046113
HpFuturesmart 5< 2507252_046164
HpFuturesmart 5< 2507252_046133
HpFuturesmart 5< 2507252_046162
HpFuturesmart 5< 2507252_046125
HpFuturesmart 5< 2507252_046109
HpFuturesmart 5< 2507252_046143
HpFuturesmart 5< 2507252_046156

Showing 50 of 53 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-0407?
Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store.
How severe is CVE-2024-0407?
CVE-2024-0407 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2024-0407?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-0407?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST