MEDIUM · 4.3

CVE-2009-2684

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to...

Vulnerability Description

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HpCm8050 MfpAll versions
HpCm8060 MfpAll versions
HpColor Laserjet 3000NAll versions
HpColor Laserjet 3600NAll versions
HpColor Laserjet 3800NAll versions
HpColor Laserjet 4700NAll versions
HpColor Laserjet 4730 MfpAll versions
HpColor Laserjet 6040 MfpAll versions
HpColor Laserjet Cm4730 MfpAll versions
HpColor Laserjet Cp3505All versions
HpColor Laserjet Cp4005NAll versions
HpColor Laserjet Cp6015All versions
HpDs 9200CAll versions
HpDs 9250CAll versions
HpLaserjet 2410All versions
HpLaserjet 2420All versions
HpLaserjet 2430NAll versions
HpLaserjet 4240All versions
HpLaserjet 4250NAll versions
HpLaserjet 4345 MfpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2684?

CVE-2009-2684 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to...

How severe is CVE-2009-2684?

CVE-2009-2684 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2684?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Cm8050 Mfp, Hp Cm8060 Mfp, Hp Color Laserjet 3000N, Hp Color Laserjet 3600N, Hp Color Laserjet 3800N.