Vulnerability Database

385,445

Total vulnerabilities in the database

CVE-2019-6334 — hp / futuresmart_3

HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.

  • Published: Oct 16, 2019
  • Updated: Sep 15, 2026
  • CVE: CVE-2019-6334
  • Severity: Critical
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software Affected versions
hp / futuresmart_3 < 2309021_581893
hp / futuresmart_3 < 2309021_581898
hp / futuresmart_4 < 2408067_049135
hp / futuresmart_3 < 2309021_581886
hp / futuresmart_4 < 2408067_049141
hp / futuresmart_3 < 2309021_581895
hp / futuresmart_4 < 2408067_049131
hp / futuresmart_4 < 2408067_049158
hp / futuresmart_3 < 2309021_581902
hp / futuresmart_4 < 2408067_049164
hp / futuresmart_3 < 2309021_581899
hp / futuresmart_4 < 2408067_049127
hp / futuresmart_3 < 2309021_581889
hp / futuresmart_4 < 2408071_000209
hp / futuresmart_3 < 2309021_581900
hp / futuresmart_4 < 2408067_049134
hp / futuresmart_4 < 2408071_000205
hp / futuresmart_3 < 2309021_581892
hp / futuresmart_4 < 2408071_000142
hp / futuresmart_4 < 2408071_000121
hp / futuresmart_4 < 2408071_000187
hp / futuresmart_3 < 2309021_581909
hp / futuresmart_3 < 2309021_581910
hp / futuresmart_4 < 2408067_049137
hp / futuresmart_3 < 2309021_581897
hp / futuresmart_4 < 2408067_049133
hp / futuresmart_3 < 2309021_581908
hp / futuresmart_3 < 2309021_581906
hp / futuresmart_4 < 2408067_049139
hp / futuresmart_3 < 2309021_581905
hp / futuresmart_3 < 2309021_581882
hp / futuresmart_4 < 2408067_049129
hp / futuresmart_3 < 2309021_581896
hp / futuresmart_4 < 2408067_049128
hp / futuresmart_3 < 2309021_581901
hp / futuresmart_3 < 2309021_581888
hp / futuresmart_4 < 2408067_049155
hp / futuresmart_4 < 2408067_049154
hp / futuresmart_3 < 2309021_581887
hp / futuresmart_4 < 2408067_049146
hp / futuresmart_4 < 2408067_049153
hp / futuresmart_3 < 2309021_581903
hp / futuresmart_4 < 2408067_049167
hp / futuresmart_3 < 2309021_581883
hp / futuresmart_4 < 2408071_000203
hp / futuresmart_4 < 2408071_000190
hp / futuresmart_4 < 2408071_000197
hp / futuresmart_3 < 2309021_581904
hp / futuresmart_4 < 2408067_049132
hp / futuresmart_4 < 2408071_000181
hp / futuresmart_4 < 2408071_000120
hp / futuresmart_4 < 2408071_000103
hp / futuresmart_3 < 2309021_581884
hp / futuresmart_4 < 2408067_049136
hp / futuresmart_3 < 2309021_581885
hp / futuresmart_4 < 2408067_049130
hp / futuresmart_4 < 2408067_049143
hp / futuresmart_4 < 2408067_049156
hp / futuresmart_3 < 2309021_581890
hp / futuresmart_4 < 2408067_049165
hp / futuresmart_4 < 2408071_000196
hp / futuresmart_3 < 2309021_581891
hp / futuresmart_4 < 2408071_000199
hp / futuresmart_3 < 2309021_581894
hp / futuresmart_4 < 2408067_049160
hp / futuresmart_4 < 2408067_049162

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.