CVE-2017-2747
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- hp/t790 firmware · hp/t795 firmware · hp/t1300 firmware · hp/t2300 firmware · hp/t920 firmware · hp/t930 firmware · hp/t1500 firmware · hp/t1530 firmware · hp/t2500 firmware · hp/t2530 firmware · hp/t3500 firmware · hp/110 firmware · hp/310 firmware · hp/330 firmware · hp/360 firmware · hp/370 firmware · hp/315 firmware · hp/335 firmware · hp/365 firmware · hp/375 firmware · +2 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/c05624457Vendor Advisory
- https://support.hp.com/us-en/document/c05624457Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.