CVE-2017-2750
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise printers before 2308937_578479,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise printers before 2308937_578479, 2405087_018548, and other firmware versions.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.92% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- hp/l2683a firmware · hp/l2717a firmware · hp/l2762a firmware · hp/j7z13a firmware · hp/z5g79a firmware · hp/l3u42a firmware · hp/j7z08a firmware · hp/j7z14a firmware · hp/z5g77a firmware · hp/j7z03a firmware · hp/j7z07a firmware · hp/j7z05a firmware · hp/l3u43a firmware · hp/g1w41a firmware · hp/g1w41v firmware · hp/j7z06a firmware · hp/g1w46a firmware · hp/g1w46v firmware · hp/g1w47v firmware · hp/l3u44a firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- http://www.securityfocus.com/bid/101965Third Party Advisory, VDB Entry
- https://support.hp.com/us-en/document/c05839270Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/101965Third Party Advisory, VDB Entry
- https://support.hp.com/us-en/document/c05839270Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.