ZeroHour

CVE-2024-5143

CVSS 3.1
6.8 medium
EPSS
<1%p34
Published
()
Modified
Description

A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.

Vendors
hp
Products
w1a78a firmware, w1a80a firmware, w1a79a firmware, w1a82a firmware, w1a81a firmware, w1a77a firmware, w1a76a firmware, w1a75a firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.