CVE-2011-0279
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to…
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- hp/multifunction peripheral digital sending software
- Source
- hp-security-alert@hp.com
References
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02738104
- http://secunia.com/advisories/43618Vendor Advisory
- http://www.securityfocus.com/bid/46679
- http://www.securitytracker.com/id?1025155
- http://www.vupen.com/english/advisories/2011/0561
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65866
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02738104
- http://secunia.com/advisories/43618Vendor Advisory
- http://www.securityfocus.com/bid/46679
- http://www.securitytracker.com/id?1025155
- http://www.vupen.com/english/advisories/2011/0561
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65866
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.