Vulnerability CVE-2017-2747


Published: 2018-01-23

Description:
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

Type:

CWE-255

(Credentials Management)

Vendor: HP
Product: 560 firmware 
Version: storm_00_05_01.5;
Product: 570 firmware 
Version: storm_00_05_01.5;
Product: 315 firmware 
Version: nexus_03_12_00.14;
Product: 335 firmware 
Version: nexus_03_12_00.14;
Product: 365 firmware 
Version: nexus_03_12_00.14;
Product: 375 firmware 
Version: nexus_03_12_00.14;
Product: 360 firmware 
Version: nexus_01_12_00.10;
Product: 370 firmware 
Version: nexus_01_12_00.10;
Product: 310 firmware 
Version: nexus_01_12_00.10;
Product: 330 firmware 
Version: nexus_01_12_00.10;
Product: 110 firmware 
Version: nexus_00_04_53.8;
Product: T1500 firmware 
Version: mry_04_05_00.4;
Product: T930 firmware 
Version: mry_04_05_00.4;
Product: T2530 firmware 
Version: mry_04_05_00.4;
Product: T1530 firmware 
Version: mry_04_05_00.4;
Product: T920 firmware 
Version: mry_04_05_00.4;
Product: T2500 firmware 
Version: mry_04_05_00.4;
Product: T795 firmware 
Version: ig_11_00_00.09;
Product: T2300 firmware 
Version: ig_11_00_00.09;
Product: T1300 firmware 
Version: ig_11_00_00.09;
Product: T790 firmware 
Version: ig_11_00_00.09;
Product: T3500 firmware 
Version: aeneas_03_04_00.8;

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://support.hp.com/us-en/document/c05624457

Related CVE
CVE-2018-7100
A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could...
CVE-2018-7099
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.
CVE-2018-7098
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow directory traversal.
CVE-2018-7097
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow cross-site request forgery.
CVE-2018-7096
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow code execution.
CVE-2018-7095
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remotely to allow access restriction bypass.
CVE-2018-7093
A security vulnerability in HPE Integrated Lights-Out 3 prior to v1.90, iLO 4 prior to v2.60, iLO 5 prior to v1.30, Moonshot Chassis Manager firmware prior to v1.58, and Moonshot Component Pack prior to v2.55 could be remotely exploited to create a d...
CVE-2018-5925
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.

Copyright 2018, cxsecurity.com

 

Back to Top