Vulnerability CVE-2017-2747


Published: 2018-01-23

Description:
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

Type:

CWE-255

(Credentials Management)

Vendor: HP
Product: 560 firmware 
Version: storm_00_05_01.5;
Product: 570 firmware 
Version: storm_00_05_01.5;
Product: 315 firmware 
Version: nexus_03_12_00.14;
Product: 335 firmware 
Version: nexus_03_12_00.14;
Product: 365 firmware 
Version: nexus_03_12_00.14;
Product: 375 firmware 
Version: nexus_03_12_00.14;
Product: 360 firmware 
Version: nexus_01_12_00.10;
Product: 370 firmware 
Version: nexus_01_12_00.10;
Product: 310 firmware 
Version: nexus_01_12_00.10;
Product: 330 firmware 
Version: nexus_01_12_00.10;
Product: 110 firmware 
Version: nexus_00_04_53.8;
Product: T1500 firmware 
Version: mry_04_05_00.4;
Product: T930 firmware 
Version: mry_04_05_00.4;
Product: T2530 firmware 
Version: mry_04_05_00.4;
Product: T1530 firmware 
Version: mry_04_05_00.4;
Product: T920 firmware 
Version: mry_04_05_00.4;
Product: T2500 firmware 
Version: mry_04_05_00.4;
Product: T795 firmware 
Version: ig_11_00_00.09;
Product: T2300 firmware 
Version: ig_11_00_00.09;
Product: T1300 firmware 
Version: ig_11_00_00.09;
Product: T790 firmware 
Version: ig_11_00_00.09;
Product: T3500 firmware 
Version: aeneas_03_04_00.8;

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://support.hp.com/us-en/document/c05624457

Related CVE
CVE-2018-6494
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
CVE-2018-6493
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injec...
CVE-2018-6492
Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability ...
CVE-2018-6490
Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.
CVE-2017-8984
A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.
CVE-2017-8983
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
CVE-2017-8982
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
CVE-2017-8981
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.

Copyright 2018, cxsecurity.com

 

Back to Top