Vulnerability CVE-2017-2747


Published: 2018-01-23

Description:
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.

Type:

CWE-noinfo

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
HP -> 110 firmware 
HP -> T2530 firmware 
HP -> 310 firmware 
HP -> T3500 firmware 
HP -> 315 firmware 
HP -> T790 firmware 
HP -> 330 firmware 
HP -> T795 firmware 
HP -> 335 firmware 
HP -> T920 firmware 
HP -> 360 firmware 
HP -> T930 firmware 
HP -> 365 firmware 
HP -> 370 firmware 
HP -> 375 firmware 
HP -> 560 firmware 
HP -> 570 firmware 
HP -> T1300 firmware 
HP -> T1500 firmware 
HP -> T1530 firmware 
HP -> T2300 firmware 
HP -> T2500 firmware 

 References:
https://support.hp.com/us-en/document/c05624457

Copyright 2020, cxsecurity.com

 

Back to Top