cbcvebase.
CVE-2024-5143
published 2024-05-23

CVE-2024-5143: A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By…

PriorityP335medium6.8CVSS 3.1
AVNACLPRHUINSCCHINAN
EPSS
0.40%
32.3th percentile
A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.

Affected

9 ranges
VendorProductVersion rangeFixed in
hpw1a75a_firmware< 002_2413A002_2413A
hpw1a76a_firmware< 002_2413A002_2413A
hpw1a77a_firmware< 002_2413A002_2413A
hpw1a78a_firmware< 002_2413A002_2413A
hpw1a79a_firmware< 002_2413A002_2413A
hpw1a80a_firmware< 002_2413A002_2413A
hpw1a81a_firmware< 002_2413A002_2413A
hpw1a82a_firmware< 002_2413A002_2413A
hp_inccertain_hp_laserjet_pro_printers

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.