Lucene search

K
hpHP Product Security Response TeamHPSBPI03849
HistoryJun 12, 2023 - 12:00 a.m.

Certain HP Enterprise LaserJet MFP Products – Potential Buffer Overflow, Remote Code Execution

2023-06-1200:00:00
HP Product Security Response Team
support.hp.com
2
hp enterprise
laserjet
mfp
potential security vulnerability
buffer overflow
remote code execution
printer firmware
software

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%

A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.

Update the printer firmware.

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.1%