SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-1526

Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.

MEDIUM 4.6EPSS 1.19%

Does this matter?

Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.

Description

Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.19% probability · 66th percentile
CISA KEV
Not listed
Affected
hp/designjet z6 firmware · hp/designjet z6dr firmware · hp/designjet z9 firmware · hp/designjet z9dr firmware · hp/designjet z9\+ pro firmware · hp/pagewide xl 4700 · hp/pagewide xl 4500 · hp/pagewide xl 4100 · hp/pagewide xl 4600 · hp/pagewide xl 8000
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.