Vulnerability CVE-2017-2747


Published: 2018-01-23

Description:
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

Type:

CWE-255

(Credentials Management)

Vendor: HP
Product: 560 firmware 
Version: storm_00_05_01.5;
Product: 570 firmware 
Version: storm_00_05_01.5;
Product: 315 firmware 
Version: nexus_03_12_00.14;
Product: 335 firmware 
Version: nexus_03_12_00.14;
Product: 365 firmware 
Version: nexus_03_12_00.14;
Product: 375 firmware 
Version: nexus_03_12_00.14;
Product: 360 firmware 
Version: nexus_01_12_00.10;
Product: 370 firmware 
Version: nexus_01_12_00.10;
Product: 310 firmware 
Version: nexus_01_12_00.10;
Product: 330 firmware 
Version: nexus_01_12_00.10;
Product: 110 firmware 
Version: nexus_00_04_53.8;
Product: T1500 firmware 
Version: mry_04_05_00.4;
Product: T930 firmware 
Version: mry_04_05_00.4;
Product: T2530 firmware 
Version: mry_04_05_00.4;
Product: T1530 firmware 
Version: mry_04_05_00.4;
Product: T920 firmware 
Version: mry_04_05_00.4;
Product: T2500 firmware 
Version: mry_04_05_00.4;
Product: T795 firmware 
Version: ig_11_00_00.09;
Product: T2300 firmware 
Version: ig_11_00_00.09;
Product: T1300 firmware 
Version: ig_11_00_00.09;
Product: T790 firmware 
Version: ig_11_00_00.09;
Product: T3500 firmware 
Version: aeneas_03_04_00.8;

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://support.hp.com/us-en/document/c05624457

Related CVE
CVE-2018-6492
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability ...
CVE-2018-6490
Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.
CVE-2017-8984
A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.
CVE-2017-8983
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
CVE-2017-8982
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
CVE-2017-8981
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.
CVE-2017-8980
A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
CVE-2017-8979
Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.

Copyright 2018, cxsecurity.com

 

Back to Top