← Security Alerts

CVE-2019-6332

HP Inc. · published 2020-01-09

Source record Collected from the National Vulnerability Database (NVD)

Description

Description by HP Inc. via the CVE Program.

A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink Advantage 2600 All-in-One Printer series model numbers V1N02A - V1N02B, Y5Z00A - Y5Z04B; HP DeskJet Ink Advantage 5000 All-in-One Printer series model numbers M2U86A - M2U89B; HP DeskJet Ink Advantage 5200 All-in-One Printer series model numbers M2U76A - M2U78B; HP ENVY 5000 All-in-One Printer series model numbers M2U85A - M2U85B, M2U91A - M2U94B, Z4A54A - Z4A74A; HP ENVY Photo 6200 All-in-One Printer series model numbers K7G18A-K7G26B, K7S21B, Y0K13D - Y0K15A; HP ENVY Photo 7100 All-in-One Printer series model numbers 3XD89A, K7G93A-K7G99A, Z3M37A - Z3M52A; HP ENVY Photo 7800 All-in-One Printer series model numbers K7R96A, K7S00A - K7S10D, Y0G42D - Y0G52B; HP Ink Tank Wireless 410 series model numbers Z4B53A - Z4B55A, Z6Z95A - Z6Z99A, 4DX94A - 4DX95A, 4YF79A, Z7A01A; HP OfficeJet 5200 All-in-One Printer series model numbers M2U75A, M2U81A-M2U84B, Z4B12A - Z4B14A, Z4B27A - Z4B29A; HP Smart Tank Wireless 450 series model numbers Z4B56A, Z6Z96A - Z6Z98A.

Status at the source

Affected products, as the source lists them

VendorProductVersions
HP Inc.HP DeskJet 2600 All-in-One Printer series4UJ28B: affected
V1N01A - V1N08A: affected
Y5H60A - Y5H80A: affected
HP Inc.HP DeskJet Ink Advantage 2600 All-in-One Printer seriesV1N02A - V1N02B: affected
Y5Z00A - Y5Z04B: affected
HP Inc.HP DeskJet Ink Advantage 5000 All-in-One Printer seriesM2U86A - M2U89B: affected
HP Inc.HP DeskJet Ink Advantage 5200 All-in-One Printer seriesM2U76A - M2U78B: affected
HP Inc.HP ENVY 5000 All-in-One Printer seriesM2U85A - M2U85B: affected
M2U91A - M2U94B: affected
Z4A54A - Z4A74A: affected
HP Inc.HP ENVY Photo 6200 All-in-One Printer seriesK7G18A-K7G26B: affected
K7S21B: affected
Y0K13D - Y0K15A: affected
HP Inc.HP ENVY Photo 7100 All-in-One Printer series3XD89A: affected
K7G93A-K7G99A: affected
Z3M37A - Z3M52A: affected
HP Inc.HP ENVY Photo 7800 All-in-One Printer seriesK7R96A: affected
K7S00A - K7S10D: affected
Y0G42D - Y0G52B: affected
HP Inc.HP Ink Tank Wireless 410 seriesZ4B53A - Z4B55A: affected
Z6Z95A - Z6Z99A: affected
4DX94A - 4DX95A: affected
4YF79A: affected
Z7A01A: affected
HP Inc.HP OfficeJet 5200 All-in-One Printer seriesM2U75A: affected
M2U81A-M2U84B: affected
Z4B12A - Z4B14A: affected
Z4B27A - Z4B29A: affected
HP Inc.HP Smart Tank Wireless 450 seriesZ4B56A: affected
Z6Z96A - Z6Z98A: affected
Products named in NVD's CPE match criteria (50)
  • cpe:2.3:o:hp:deskjet_2600_4uj28b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_2600_v1n01a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_2600_v1n08a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_2600_y5h60a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_2600_y5h80a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_2600_v1n02a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_2600_v1n02b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_2600_y5z00a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_2600_y5z04b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_5000_m2u86a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_5000_m2u89b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_5200_m2u76a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:deskjet_ink_advantage_5200_m2u78b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_m2u85a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_m2u85b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_m2u91a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_m2u94b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_z4a54a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_5000_z4a74a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_6200_k7g18a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_6200_k7g26b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_6200_k7s21b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_6200_y0k13d__firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_6200_y0k15a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7100_3xd89a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7100_k7g93a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7100_k7g99a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7100_z3m37a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7100_z3m52a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7800_k7r96a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7800_k7s00a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7800_k7s10d_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7800_y0g42d_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:envy_photo_7800_y0g52b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_z4b53a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_z4b55a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_z6z95a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_z6z99a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_4dx94a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_4dx95a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_4yf79a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:ink_tank_wireless_410_z7a01a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_m2u75a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_m2u81a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_m2u84b_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_z4b12a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_z4b14a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_z4b27a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:officejet_5200_z4b29a_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:hp:smart_tank_wireless_450_z4b56a_firmware:*:*:*:*:*:*:*:*

DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.

Scores, as their sources published them

DeSpy does not score records. These are the sources' own values.

Weaknesses

CWE-79

Sources

References the source lists

Source dates: published 2020-01-09, last changed 2026-06-17. DeSpy's copy of this version is dated 2026-09-28.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →