Remote Code Execution Vulnerability in HP Point of Sale Products
CVE-2014-7894

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
9 March 2015

Summary

The OLE Point of Sale (OPOS) drivers prior to version 1.13.003 on HP Point of Sale Windows PCs are susceptible to a vulnerability that enables remote attackers to execute arbitrary code. This exploitation can occur through various vectors involving OPOSPOSPrinter.ocx interface, affecting multiple types of printers including PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, and Value Serial/USB Receipt printers.

References

EPSS Score

46% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.