Vulnerability CVE-2018-5923


Published: 2019-03-27

Description:
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.

Type:

CWE-347

(Improper Verification of Cryptographic Signature)

Vendor: HP
Product: Color laserjet managed mfp e67550dh firmware 
Version: 2406087_000017;
Product: Color laserjet enterprise flow mfp m681f firmware 
Version: 2406087_000017;
Product: Color laserjet managed flow mfp e67560z firmware 
Version: 2406087_000017;
Product: Color laserjet enterprise mfp m682dh firmware 
Version: 2406087_000017;
Product: Color laserjet managed mfp e67560dh firmware 
Version: 2406087_000017;
Product: Color laserjet managed flow mfp e67550f firmware 
Version: 2406087_000017;
Product: Color laserjet enterprise mfp m681dh firmware 
Version: 2406087_000017;
Product: Color laserjet enterprise m653dn firmware 
Version: 2406087_000016;
Product: Color laserjet managed e65050dn firmware 
Version: 2406087_000016;
Product: Color laserjet enterprise m652n firmware 
Version: 2406087_000016;
Product: Laserjet enterprise m806 firmware 
Version: 2406048_029646;
Product: Laserjet enterprise mfp m725 firmware 
Version: 2406048_029644;
Product: Color laserjet managed e55040dw firmware 
Version: 2406048_029643;
Product: Officejet enterprise color x555xh firmware 
Version: 2406048_029642;
Product: Officejet enterprise color x555dn firmware 
Version: 2406048_029642;
Product: Laserjet enterprise 800 color mfp m880 firmware 
Version: 2406048_029641;
Product: Laserjet managed e50045dw firmware 
Version: 2406048_029640;
Product: Laserjet enterprise m609dh firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m607n firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m609x firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m608dn firmware 
Version: 2406048_029638;
Product: Laserjet managed e60065dn firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m608x firmware 
Version: 2406048_029638;
Product: Laserjet managed e60075dn firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m609dn firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m608dh firmware 
Version: 2406048_029638;
Product: Laserjet managed e60055dn firmware 
Version: 2406048_029638;
Product: Laserjet enterprise m608n firmware 
Version: 2406048_029638;
Product: Laserjet managed e60065x firmware 
Version: 2406048_029638;
Product: Pagewide enterprise color x556xh firmware 
Version: 2406048_029637;
Product: Pagewide enterprise color x556dn firmware 
Version: 2406048_029637;
Product: Pagewide managed color e55650dn firmware 
Version: 2406048_029637;
Product: Officejet enterprise color mfp x585 firmware 
Version: 2406048_029636;
Product: Officejet enterprise color flow mfp x585 firmware 
Version: 2406048_029636;
Product: Laserjet enterprise flow mfp m525c firmware 
Version: 2406048_029635;
Product: Laserjet enterprise 500 mfp m525f firmware 
Version: 2406048_029635;
Product: Laserjet enterprise 500 color mfp m575dn firmware 
Version: 2406048_029634;
Product: Laserjet enterprise color flow mfp m575c firmware 
Version: 2406048_029634;
Product: Color laserjet m680 firmware 
Version: 2406048_029633;
Product: Color laserjet enterprise m651 firmware 
Version: 2406048_029632;
Product: Laserjet enterprise mfp m630 firmware 
Version: 2406048_029631;
Product: Laserjet enterprise flow mfp m630z firmware 
Version: 2406048_029631;
Product: Laserjet managed flow mfp e62575z firmware 
Version: 2406048_029629;
Product: Laserjet enterprise mfp m631z firmware 
Version: 2406048_029629;
Product: Laserjet enterprise flow mfp m631h firmware 
Version: 2406048_029629;
Product: Laserjet managed flow mfp e62555dn firmware 
Version: 2406048_029629;
Product: Laserjet enterprise mfp m632h firmware 
Version: 2406048_029629;
Product: Laserjet managed mfp e62565hs firmware 
Version: 2406048_029629;
Product: Laserjet enterprise flow mfp m633z firmware 
Version: 2406048_029629;
Product: Laserjet managed flow mfp e62565z firmware 
Version: 2406048_029629;
Product: Laserjet enterprise mfp m631dn firmware 
Version: 2406048_029629;
Product: Laserjet managed flow mfp e52545c firmware 
Version: 2406048_029629;
Product: Laserjet enterprise mfp m632fht firmware 
Version: 2406048_029629;
Product: Laserjet managed mfp e62555dn firmware 
Version: 2406048_029629;
Product: Laserjet enterprise flow mfp m632z firmware 
Version: 2406048_029629;
Product: Laserjet managed flow mfp e62565h firmware 
Version: 2406048_029629;
Product: Laserjet enterprise mfp m633fh firmware 
Version: 2406048_029629;
Product: Laserjet managed e60075x firmware 
Version: 2406048_029628;
Product: Laserjet managed mfp e52545dn firmware 
Version: 2406048_029628;
Product: Laserjet enterprise mfp m527 firmware 
Version: 2406048_029628;
Product: Color laserjet managed flow mfp e57540dn firmware 
Version: 2406048_029627;
Product: Color laserjet enterprise mfp m577 firmware 
Version: 2406048_029627;
Product: Color laserjet managed flow mfp e57540c firmware 
Version: 2406048_029627;
Product: Scanjet enterprise flow n9120 document flatbed scanner firmware 
Version: 2406048_029625;
Product: Pagewide managed color flow mfp e58650z firmware 
Version: 2406048_029624;
Product: Pagewide enterprise color mfp 586dn firmware 
Version: 2406048_029624;
Product: Pagewide managed color mfp e58650dn firmware 
Version: 2406048_029624;
Product: Pagewide enterprise color flow mfp 586z firmware 
Version: 2406048_029624;
Product: Pagewide enterprise color mfp 586f firmware 
Version: 2406048_029624;
Product: Digital sender flow 8500 fn2 document capture workstation firmware 
Version: 2406048_029623;
Product: Pagewide managed color flow mfp e77660zs firmware 
Version: 2406048_029621;
Product: Pagewide enterprise color mpf 785zs firmware 
Version: 2406048_029621;
Product: Laserjet enterprise 800 color m855 firmware 
Version: 2406048_029621;
Product: Pagewide managed color flow mfp e77650zs firmware 
Version: 2406048_029621;
Product: Pagewide enterprise color mpf 780dn firmware 
Version: 2406048_029621;
Product: Pagewide managed color mfp e77650dns firmware 
Version: 2406048_029621;
Product: Pagewide managed color flow mfp e77660z firmware 
Version: 2406048_029621;
Product: Pagewide enterprise color mpf 785f firmware 
Version: 2406048_029621;
Product: Pagewide managed color flow mfp e77660zts firmware 
Version: 2406048_029621;
Product: Pagewide managed color flow mfp e77650z firmware 
Version: 2406048_029621;
Product: Pagewide managed color mfp e77650dn firmware 
Version: 2406048_029621;
Product: Pagewide managed color flow mfp e77660dn firmware 
Version: 2406048_029621;
Product: Pagewide enterprise color mpf 780f firmware 
Version: 2406048_029621;
Product: Pagewide managed color e75160dn firmware 
Version: 2406048_029619;
Product: Pagewide enterprise color 765dn firmware 
Version: 2406048_029619;
Product: Laserjet managed mfp e82560dn firmware 
Version: 2406048_029617;
Product: Laserjet managed flow mfp e82550 firmware 
Version: 2406048_029617;
Product: Laserjet managed mfp e82550 firmware 
Version: 2406048_029617;
Product: Laserjet managed flow mfp e82540 firmware 
Version: 2406048_029617;
Product: Laserjet managed flow mfp e82560z firmware 
Version: 2406048_029617;
Product: Laserjet managed mfp e82540 firmware 
Version: 2406048_029617;
Product: Color laserjet managed flow mfp e77830z firmware 
Version: 2406048_029616;
Product: Color laserjet managed mfp e77822 firmware 
Version: 2406048_029616;
Product: Color laserjet managed mfp e77830dn firmware 
Version: 2406048_029616;
Product: Color laserjet managed flow mfp e77825 firmware 
Version: 2406048_029616;
Product: Color laserjet managed mfp e77825 firmware 
Version: 2406048_029616;
Product: Color laserjet managed flow mfp e77822 firmware 
Version: 2406048_029616;
Product: Color laserjet managed mfp e87640 firmware 
Version: 2406048_029615;
Product: Color laserjet managed mfp e87650 firmware 
Version: 2406048_029615;
Product: Color laserjet managed flow mfp e87640 firmware 
Version: 2406048_029615;

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
https://support.hp.com/us-en/document/c06169434

Related CVE
CVE-2019-11986
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVE-2019-11985
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVE-2019-11984
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVE-2019-11983
A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
CVE-2019-11982
A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.
CVE-2019-11980
A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVE-2019-11979
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVE-2019-11978
A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Copyright 2019, cxsecurity.com

 

Back to Top