« Volver al listado

CVE-2024-6620

Estado: AplazadaBaja (3.5)—

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6620",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6620",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-30T14:17:52.818483Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@honeywell.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@honeywell.com",
      "affectedData": [
        {
          "vendor": "Honeywell",
          "product": "PC42t, PC42tp, and PC42d (Common Firmware)",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "T10.20.060398",
                  "status": "unaffected"
                }
              ],
              "version": "T10.19.020016",
              "lessThan": "T10.20.060398",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-07-29T20:15:03.910",
  "references": [
    {
      "url": "https://sps.honeywell.com/us/en/support/productivity/cyber-security-notifications",
      "source": "psirt@honeywell.com"
    },
    {
      "url": "https://sps.honeywell.com/us/en/support/productivity/cyber-security-notifications",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@honeywell.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        },
        {
          "lang": "en",
          "value": "CWE-602"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398."
    },
    {
      "lang": "es",
      "value": "Las impresoras Honeywell PC42t, PC42tp y PC42d, T10.19.020016 a T10.20.060398, contienen una vulnerabilidad de Cross Site Scripting. Un atacante podría potencialmente inyectar código malicioso que podría conducir a la divulgación de información, el robo de sesiones o client-side request forgery. Honeywell recomienda actualizar a la versión más reciente de este firmware, PC42 Printer Firmware Version 20.6 T10.20.060398."
    }
  ],
  "lastModified": "2026-06-17T08:18:22.003",
  "sourceIdentifier": "psirt@honeywell.com"
}