Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-3272


Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.


Published

2012-12-06T11:45:47.060

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware hp color_laserjet_cm3530 ≤ 53.190.8 Yes
Hardware hp color_laserjet_cm60xx ≤ 53.190.8 Yes
Hardware hp color_laserjet_cp3525 ≤ 06.140.3.17 Yes
Hardware hp color_laserjet_cp4xxx ≤ 07.120.5 Yes
Hardware hp color_laserjet_cp6015 ≤ 04.160.2 Yes
Hardware hp laserjet_p3015 ≤ 07.140.2 Yes
Hardware hp laserjet_p4xxx ≤ 04.170.2 Yes

References