Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24620
HistoryApr 10, 2020 - 12:59 a.m.

Arbitrary Code Execution

2020-04-1000:59:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.11 Low

EPSS

Percentile

95.1%

hplip is vulnerable to arbitrary code execution. The vulnerability exists as a flaw was found in the way certain HPLIP tools discovered devices using the SNMP protocol. If a user ran certain HPLIP tools that search for supported devices using SNMP, and a malicious user is able to send specially-crafted SNMP responses, it could cause those HPLIP tools to crash or, possibly, execute arbitrary code with the privileges of the user running them.

References