SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-2741

A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D.

CRITICAL 9.8EPSS 84.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 84.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
84.61% probability · 100th percentile
CISA KEV
Not listed
Affected
hp/j9v82a firmware · hp/j9v82b firmware · hp/j9v82c firmware · hp/j9v82d firmware · hp/j6u55a firmware · hp/j6u55b firmware · hp/j6u55c firmware · hp/j6u55d firmware · hp/k9z76a firmware · hp/k9z76d firmware · hp/d3q17a firmware · hp/d3q17c firmware · hp/d3q17d firmware · hp/d3q21a firmware · hp/d3q21c firmware · hp/d3q21d firmware · hp/d3q20a firmware · hp/d3q20b firmware · hp/d3q20c firmware · hp/d3q20d firmware · +18 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.