CVE-2024-5143

A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:w1a75a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a75a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hp:w1a76a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a76a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hp:w1a77a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a77a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hp:w1a81a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a81a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hp:w1a82a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a82a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hp:w1a79a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a79a:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hp:w1a80a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a80a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hp:w1a78a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a78a:-:*:*:*:*:*:*:*

History

26 Jan 2026, 13:53

Type Values Removed Values Added
CPE cpe:2.3:h:hp:w1a77a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a75a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a81a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a78a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a82a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a79a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a82a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a81a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a78a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a79a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a76a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a75a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a77a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a80a:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:w1a80a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:w1a76a:-:*:*:*:*:*:*:*
References () https://support.hp.com/us-en/document/ish_10643804-10643841-16/HPSBPI03941 - () https://support.hp.com/us-en/document/ish_10643804-10643841-16/HPSBPI03941 - Vendor Advisory
First Time Hp w1a76a Firmware
Hp w1a78a
Hp w1a82a
Hp w1a81a
Hp w1a81a Firmware
Hp w1a77a
Hp w1a80a
Hp w1a75a
Hp w1a77a Firmware
Hp w1a80a Firmware
Hp w1a75a Firmware
Hp
Hp w1a78a Firmware
Hp w1a79a
Hp w1a76a
Hp w1a82a Firmware
Hp w1a79a Firmware

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10643804-10643841-16/HPSBPI03941 - () https://support.hp.com/us-en/document/ish_10643804-10643841-16/HPSBPI03941 -

31 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
Summary
  • (es) Un usuario con privilegios administrativos del dispositivo puede cambiar la configuración del servidor SMTP existente en el dispositivo, sin tener que volver a ingresar las credenciales del servidor SMTP. Al redirigir el tráfico de envío a correo electrónico al nuevo servidor, es posible que las credenciales originales del servidor SMTP queden expuestas.

23 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-23 17:15

Updated : 2026-01-26 13:53


NVD link : CVE-2024-5143

Mitre link : CVE-2024-5143

CVE.ORG link : CVE-2024-5143


JSON object : View

Products Affected

hp

  • w1a75a
  • w1a77a
  • w1a81a_firmware
  • w1a78a_firmware
  • w1a76a_firmware
  • w1a79a_firmware
  • w1a80a_firmware
  • w1a75a_firmware
  • w1a82a_firmware
  • w1a77a_firmware
  • w1a78a
  • w1a81a
  • w1a80a
  • w1a76a
  • w1a79a
  • w1a82a
CWE
CWE-306

Missing Authentication for Critical Function