HP LaserJet Printers Classic Buffer Overflow (CVE-2019-6327)

critical Tenable OT Security Plugin ID 505936

Synopsis

The remote OT asset is affected by a vulnerability.

Description

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v.
20190426) may have an IPP Parser potentially vulnerable to Buffer Overflow.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://support.hp.com/us-en/document/c06356322

Plugin Details

Severity: Critical

ID: 505936

File Name: tenable_ot_hp_CVE-2019-6327.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 8/3/2026

Updated: 8/3/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-6327

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:hp:laserjet_pro_m280-m281_t6b80a_firmware, cpe:/o:hp:laserjet_pro_m280-m281_t6b81a_firmware, cpe:/o:hp:laserjet_pro_m280-m281_t6b82a_firmware, cpe:/o:hp:laserjet_pro_m280-m281_t6b83a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_w2g54a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_w2g55a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_y5s50a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_y5s53a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_y5s54a_firmware, cpe:/o:hp:laserjet_pro_mfp_m28-m31_y5s55a_firmware

Required KB Items: Tenable.ot/HP

Patch Publication Date: 6/17/2019

Vulnerability Publication Date: 6/17/2019

Reference Information

CVE: CVE-2019-6327

CWE: 120