Lucene search

K
nvd[email protected]NVD:CVE-2013-6427
HistoryDec 09, 2013 - 6:55 p.m.

CVE-2013-6427

2013-12-0918:55:10
CWE-94
web.nvd.nist.gov

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.3%

upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.

Affected configurations

NVD
Node
hplinux_imaging_and_printing_projectMatch3.9.2
OR
hplinux_imaging_and_printing_projectMatch3.9.4
OR
hplinux_imaging_and_printing_projectMatch3.9.4b
OR
hplinux_imaging_and_printing_projectMatch3.9.4b
OR
hplinux_imaging_and_printing_projectMatch3.9.6
OR
hplinux_imaging_and_printing_projectMatch3.9.8
OR
hplinux_imaging_and_printing_projectMatch3.9.10
OR
hplinux_imaging_and_printing_projectMatch3.9.12
OR
hplinux_imaging_and_printing_projectMatch3.10.2
OR
hplinux_imaging_and_printing_projectMatch3.10.5
OR
hplinux_imaging_and_printing_projectMatch3.10.6
OR
hplinux_imaging_and_printing_projectMatch3.10.9
OR
hplinux_imaging_and_printing_projectMatch3.11.1
OR
hplinux_imaging_and_printing_projectMatch3.11.3
OR
hplinux_imaging_and_printing_projectMatch3.11.3a
OR
hplinux_imaging_and_printing_projectMatch3.11.3a
OR
hplinux_imaging_and_printing_projectMatch3.11.5
OR
hplinux_imaging_and_printing_projectMatch3.11.7
OR
hplinux_imaging_and_printing_projectMatch3.11.10
OR
hplinux_imaging_and_printing_projectMatch3.11.12
OR
hplinux_imaging_and_printing_projectMatch3.12.2
OR
hplinux_imaging_and_printing_projectMatch3.12.4
OR
hplinux_imaging_and_printing_projectMatch3.12.6
OR
hplinux_imaging_and_printing_projectMatch3.12.9
OR
hplinux_imaging_and_printing_projectMatch3.12.10
OR
hplinux_imaging_and_printing_projectMatch3.12.10a
OR
hplinux_imaging_and_printing_projectMatch3.12.11
OR
hplinux_imaging_and_printing_projectMatch3.13.2
OR
hplinux_imaging_and_printing_projectMatch3.13.3
OR
hplinux_imaging_and_printing_projectMatch3.13.4
OR
hplinux_imaging_and_printing_projectMatch3.13.5
OR
hplinux_imaging_and_printing_projectMatch3.13.6
OR
hplinux_imaging_and_printing_projectMatch3.13.7
OR
hplinux_imaging_and_printing_projectMatch3.13.8
OR
hplinux_imaging_and_printing_projectMatch3.13.9
OR
hplinux_imaging_and_printing_projectMatch3.13.10

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.3%