SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-5924

A security vulnerability has been identified with certain HP Inkjet printers.

CRITICAL 9.8EPSS 12.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
12.23% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
hp/t8x44 firmware · hp/3aw51a firmware · hp/a9u28b firmware · hp/d3a82a firmware · hp/v1n08a firmware · hp/y5h80a firmware · hp/d4h24b firmware · hp/f5s57a firmware · hp/k4t99b firmware · hp/k4u04b firmware · hp/t8x39 firmware · hp/1sh08 firmware · hp/3aw44a firmware · hp/a9u19a firmware · hp/d3a78b firmware · hp/4uj28b firmware · hp/v1n01a firmware · hp/y5h60a firmware · hp/d4h22a firmware · hp/j6u57b firmware · +40 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.