Attacker Value
Unknown
0
CVE-2018-5921
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Attacker Value
Unknown
(0 users assessed)Exploitability
Unknown
(0 users assessed)User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
Certain HP Enterprise Printers, HP PageWide Printers, and MFP Products 2405129_000052 and other firmware versions
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- a2w75a firmware,
- a2w76a firmware,
- a2w77a firmware,
- a2w78a firmware,
- a2w79a firmware,
- b3g84a firmware,
- b3g85a firmware,
- b3g86a firmware,
- b5l04a firmware,
- b5l05a firmware,
- b5l06a firmware,
- b5l07a firmware,
- b5l26a firmware,
- b5l39a firmware,
- b5l46a firmware,
- b5l47a firmware,
- b5l48a firmware,
- b5l49a firmware,
- b5l50a firmware,
- b5l54a firmware,
- c2s11a firmware,
- c2s11v firmware,
- c2s12a firmware,
- c2s12v firmware,
- ca251a firmware,
- cc522a firmware,
- cc523a firmware,
- cc524a firmware,
- cd644a firmware,
- cd645a firmware,
- cd646a firmware,
- cf066a firmware,
- cf067a firmware,
- cf068a firmware,
- cf069a firmware,
- cf116a firmware,
- cf117a firmware,
- cf118a firmware,
- cf367a firmware,
- cz244a firmware,
- cz245a firmware,
- cz248a firmware,
- cz249a firmware,
- cz250a firmware,
- d7p68a firmware,
- d7p70a firmware,
- d7p71a firmware,
- d7p73a firmware,
- e6b71a firmware,
- e6b73a firmware,
- f2a67a firmware,
- f2a70a firmware,
- f2a71a firmware,
- f2a76a firmware,
- f2a77a firmware,
- f2a78v firmware,
- f2a79a firmware,
- f2a80a firmware,
- f2a81a firmware,
- g1w39a firmware,
- g1w39v firmware,
- g1w40a firmware,
- g1w40v firmware,
- g1w41a firmware,
- g1w41v firmware,
- g1w46a firmware,
- g1w46v firmware,
- g1w47a firmware,
- g1w47v firmware,
- h0dc9a firmware,
- j7x28a firmware,
- j7z04a firmware,
- j7z06a firmware,
- j7z98a firmware,
- j7z99a firmware,
- j8a04a firmware,
- j8a05a firmware,
- j8a06a firmware,
- j8a10a firmware,
- j8a11a firmware,
- j8a12a firmware,
- j8a13a firmware,
- j8a16a firmware,
- j8a17a firmware,
- j8j63a firmware,
- j8j64a firmware,
- j8j65a firmware,
- j8j66a firmware,
- j8j67a firmware,
- j8j70a firmware,
- j8j71a firmware,
- j8j72a firmware,
- j8j73a firmware,
- j8j74a firmware,
- j8j76a firmware,
- j8j78a firmware,
- j8j79a firmware,
- j8j80a firmware,
- k0q14a firmware,
- k0q15a firmware,
- k0q17a firmware,
- k0q18a firmware,
- k0q19a firmware,
- k0q20a firmware,
- k0q21a firmware,
- k0q22a firmware,
- l1h45a firmware,
- l2683a firmware,
- l2762a firmware,
- l3u40a firmware,
- l3u41a firmware,
- l3u42a firmware,
- l3u43a firmware,
- l3u44a firmware,
- l3u45a firmware,
- l3u46a firmware,
- l3u47a firmware,
- l3u48a firmware,
- l3u49a firmware,
- l3u50a firmware,
- l3u51a firmware,
- l3u52a firmware,
- l3u55a firmware,
- l3u56a firmware,
- l3u57a firmware,
- l3u59a firmware,
- l3u60a,
- l3u61a firmware,
- l3u62a firmware,
- l3u63a firmware,
- l3u64a firmware,
- l3u65a firmware,
- l3u66a firmware,
- l3u67a firmware,
- l3u69a firmware,
- l3u70a firmware,
- l8z07a firmware,
- m0p32a firmware,
- m0p33a firmware,
- m0p35a firmware,
- m0p36a firmware,
- m0p39a firmware,
- m0p40a firmware,
- p7z47a firmware,
- p7z48a firmware,
- x3a59a firmware,
- x3a60a firmware,
- x3a62a firmware,
- x3a63a firmware,
- x3a65a firmware,
- x3a66a firmware,
- x3a68a firmware,
- x3a69a firmware,
- x3a71a firmware,
- x3a72a firmware,
- x3a74a firmware,
- x3a75a firmware,
- x3a77a firmware,
- x3a78a firmware,
- x3a79a firmware,
- x3a80a firmware,
- x3a81a firmware,
- x3a83a firmware,
- x3a84a firmware,
- x3a86a firmware,
- x3a87a firmware,
- x3a89a firmware,
- x3a90a firmware,
- x3a92a firmware,
- x3a93a firmware,
- z8z00a firmware,
- z8z01a firmware,
- z8z02a firmware,
- z8z03a firmware,
- z8z04a firmware,
- z8z05a firmware,
- z8z06a firmware,
- z8z07a firmware,
- z8z08a firmware,
- z8z09a firmware,
- z8z10a firmware,
- z8z11a firmware,
- z8z12a firmware,
- z8z13a firmware,
- z8z14a firmware,
- z8z15a firmware,
- z8z16a firmware,
- z8z17a firmware,
- z8z18a firmware,
- z8z19a firmware,
- z8z20a firmware,
- z8z21a firmware,
- z8z22a firmware,
- z8z23a firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: