SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5923

In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.

CRITICAL 9.8EPSS 2.61%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.61% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-347
Affected
hp/color laserjet cm4540 mfp firmware · hp/color laserjet cp5525 firmware · hp/color laserjet enterprise flow mfp m681f firmware · hp/color laserjet enterprise flow mfp m681z firmware · hp/color laserjet enterprise flow mfp m682z firmware · hp/color laserjet enterprise m552 firmware · hp/color laserjet enterprise m553 firmware · hp/color laserjet enterprise m651 firmware · hp/color laserjet enterprise m652n firmware · hp/color laserjet enterprise m652dn firmware · hp/color laserjet enterprise m653dn firmware · hp/color laserjet enterprise m653dh firmware · hp/color laserjet enterprise m653x firmware · hp/color laserjet enterprise m750 firmware · hp/color laserjet enterprise mfp m577 firmware · hp/color laserjet enterprise mfp m681dh firmware · hp/color laserjet enterprise mfp m681f firmware · hp/color laserjet enterprise mfp m682dh firmware · hp/color laserjet m680 firmware · hp/color laserjet managed e55040dw firmware · +40 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.