CVE-2019-18917: HP Deskjet Ink Advantage 5000 m2u86a Firmware

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.

Affected products

  • HP Deskjet Ink Advantage 5000 m2u86a Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Deskjet Ink Advantage 5000 m2u89b Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 m2u85a Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 m2u85b Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 m2u91a Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 m2u94b Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 z4a54a Firmware: before 003.2008a (fixed in 003.2008a)
  • HP Envy 5000 z4a74a Firmware: before 003.2008a (fixed in 003.2008a)

Published 2020-03-16. Last modified 2026-06-17.