W1a76a Firmware
by Microfocus
CVEs (15)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35175 | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model. | ||
| CVE-2023-27973 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution. | ||
| CVE-2023-27972 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution. | ||
| CVE-2023-27971 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege. | ||
| CVE-2022-28721 | Cri | 0.64 | 9.8 | 0.02 | Sep 26, 2022 | Certain HP Print Products are potentially vulnerable to Remote Code Execution. | ||
| CVE-2022-24293 | Cri | 0.64 | 9.8 | 0.07 | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | ||
| CVE-2022-24292 | Cri | 0.64 | 9.8 | 0.07 | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | ||
| CVE-2023-35178 | Hig | 0.57 | 8.8 | 0.00 | Jun 30, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs. | ||
| CVE-2023-35177 | Hig | 0.57 | 8.8 | 0.00 | Jun 30, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser. | ||
| CVE-2023-35176 | Hig | 0.57 | 8.8 | 0.00 | Jun 30, 2023 | Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device. | ||
| CVE-2025-12785 | Hig | 0.49 | 7.5 | 0.00 | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server. | ||
| CVE-2022-24291 | Hig | 0.49 | 7.5 | 0.05 | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution. | ||
| CVE-2024-5143 | Med | 0.44 | 6.8 | 0.00 | May 23, 2024 | A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed. | ||
| CVE-2025-43018 | Med | 0.34 | 5.3 | 0.00 | Jul 30, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book. | ||
| CVE-2025-12784 | Med | 0.32 | 4.9 | 0.00 | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server. |
- risk 0.64cvss 9.8epss 0.02
Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.
- risk 0.64cvss 9.8epss 0.02
Certain HP Print Products are potentially vulnerable to Remote Code Execution.
- risk 0.64cvss 9.8epss 0.07
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.
- risk 0.64cvss 9.8epss 0.07
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.
- risk 0.57cvss 8.8epss 0.00
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.
- risk 0.57cvss 8.8epss 0.00
Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.
- risk 0.57cvss 8.8epss 0.00
Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restore feature through the embedded web service on the device.
- risk 0.49cvss 7.5epss 0.00
Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.
- risk 0.49cvss 7.5epss 0.05
Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.
- risk 0.44cvss 6.8epss 0.00
A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.
- risk 0.34cvss 5.3epss 0.00
Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.
- risk 0.32cvss 4.9epss 0.00
Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.