Vulnerability Description
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet Cm4540 Mfp Cc419A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm4540 Mfp Cc419A | - |
| Hp | Color Laserjet Cm4540 Mfp Cc420A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm4540 Mfp Cc420A | - |
| Hp | Color Laserjet Cm4540 Mfp Cc421A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm4540 Mfp Cc421A | - |
| Hp | Color Laserjet Cm5525 Mfp Ce707A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce707A | - |
| Hp | Color Laserjet Cm5525 Mfp Ce708A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce708A | - |
| Hp | Color Laserjet Cm5525 Mfp Ce709A Firmware | >= 3.0, < 3.9.9 |
| Hp | Color Laserjet Cm5525 Mfp Ce709A | - |
| Hp | Color Laserjet M578 Mfp 7Zu85A Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7Zu85A | - |
| Hp | Color Laserjet M578 Mfp 7Zu86A Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7Zu86A | - |
| Hp | Color Laserjet M578 Mfp 7Zu87A Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7Zu87A | - |
| Hp | Color Laserjet M578 Mfp 7Zu88A Firmware | >= 4.0, < 4.11.2.3 |
| Hp | Color Laserjet M578 Mfp 7Zu88A | - |
Related Weaknesses (CWE)
References
- https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780Vendor Advisory
- https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780Vendor Advisory
FAQ
What is CVE-2021-3942?
CVE-2021-3942 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
How severe is CVE-2021-3942?
CVE-2021-3942 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3942?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Color Laserjet Cm4540 Mfp Cc419A Firmware, Hp Color Laserjet Cm4540 Mfp Cc419A, Hp Color Laserjet Cm4540 Mfp Cc420A Firmware, Hp Color Laserjet Cm4540 Mfp Cc420A, Hp Color Laserjet Cm4540 Mfp Cc421A Firmware.