CVE-2019-6318
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- hp/color laserjet cm4540 mfp firmware · hp/color laserjet enterprise cp5525 firmware · hp/color laserjet enterprise m553 firmware · hp/color laserjet enterprise m552 firmware · hp/color laserjet managed m553 firmware · hp/color laserjet enterprise m651 firmware · hp/color laserjet managed m651 firmware · hp/color laserjet enterprise m652 firmware · hp/color laserjet enterprise m653 firmware · hp/color laserjet enterprise m750 firmware · hp/color laserjet enterprise m855 firmware · hp/color laserjet enterprise mfp m577 firmware · hp/color laserjet enterprise flow mfp m577 firmware · hp/color laserjet enterprise mfp m680 firmware · hp/color laserjet enterprise flow mfp m680 firmware · hp/color laserjet enterprise mfp m681 firmware · hp/color laserjet enterprise flow mfp m681 firmware · hp/color laserjet enterprise mfp m682 firmware · hp/color laserjet enterprise flow mfp m682 firmware · hp/color laserjet enterprise flow mfp m880z firmware · +40 more
- Source
- hp-security-alert@hp.com
References
- https://support.hp.com/us-en/document/c06265454Vendor Advisory
- https://support.hp.com/us-en/document/c06265454Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.