CVE-2024-2301

Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:cz181a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz181a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hp:cz182a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz182a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hp:cz187a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz187a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hp:cz183a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz183a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hp:cz172a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz172a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hp:cz173a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz173a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hp:cz176a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz176a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hp:cz177a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz177a:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hp:cz178a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz178a:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hp:cz174a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz174a:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hp:cz175a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz175a:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hp:cz184a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz184a:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hp:cz185a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz185a:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:hp:cz186a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:cz186a:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-05-23 17:15

Updated : 2026-01-26 14:02


NVD link : CVE-2024-2301

Mitre link : CVE-2024-2301

CVE.ORG link : CVE-2024-2301


JSON object : View

Products Affected

hp

  • cz173a
  • cz174a_firmware
  • cz176a
  • cz177a_firmware
  • cz184a_firmware
  • cz175a_firmware
  • cz173a_firmware
  • cz183a
  • cz172a_firmware
  • cz182a_firmware
  • cz182a
  • cz187a
  • cz187a_firmware
  • cz178a_firmware
  • cz185a
  • cz181a_firmware
  • cz178a
  • cz185a_firmware
  • cz186a_firmware
  • cz181a
  • cz183a_firmware
  • cz184a
  • cz172a
  • cz175a
  • cz174a
  • cz186a
  • cz177a
  • cz176a_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')