SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-4063

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

MEDIUM 5.3EPSS 0.57%

Does this matter?

Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.

Description

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
0.57% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
hp/1kr42a firmware · hp/1kr45a firmware · hp/1kr46a firmware · hp/1kr48a firmware · hp/1kr49a firmware · hp/1kr54a firmware · hp/1kr55a firmware · hp/1kr55b firmware · hp/1kr55d firmware · hp/1mr66a firmware · hp/1mr67a firmware · hp/1mr68a firmware · hp/1mr69a firmware · hp/1mr69c firmware · hp/1mr70a firmware · hp/1mr71a firmware · hp/1mr72a firmware · hp/1mr73a firmware · hp/1mr73d firmware · hp/1mr74a firmware · +22 more
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.