SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-28416

HP has identified a security vulnerability with the I.R.I.S.

HIGH 7.8EPSS 0.38%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.38% probability · 31th percentile
CISA KEV
Not listed
Affected
hp/officejet 4650 e6g87a firmware · hp/officejet 4650 f1h96a firmware · hp/officejet 4650 f1h96b firmware · hp/officejet 4650 f1j03a firmware · hp/officejet 4650 f1j04a firmware · hp/officejet 4650 f9d37a firmware · hp/officejet 4650 k9v77a firmware · hp/officejet 4650 k9v85b firmware · hp/officejet 4651 k9v83b firmware · hp/officejet 4652 f1j02a firmware · hp/officejet 4652 f1j05b firmware · hp/officejet 4652 k9v84b firmware · hp/officejet 4654 f1j06b firmware · hp/officejet 4654 f1j07b firmware · hp/officejet 4654 k9v76a firmware · hp/officejet 4655 f1j00a firmware · hp/officejet 4655 k9v82b firmware · hp/officejet 4656 k9v81b firmware · hp/officejet 4657 v6d27b firmware · hp/officejet 4657 v6d29b firmware · +40 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.