Remote Code Execution Vulnerability in HP Point of Sale System
CVE-2014-7897

Currently unrated

Key Information:

Vendor

HP

Vendor
CVE Published:
9 March 2015

What is CVE-2014-7897?

The OPOS drivers utilized by HP Point of Sale Windows PCs are susceptible to a vulnerability that allows remote attackers to execute arbitrary code. This issue arises from improper handling of the OPOSScanner.ocx file, affecting various types of imaging and barcode scanners, including Linear, Presentation, Retail Integrated, Wireless, and 2D Value Wireless scanners. Exploiting this vulnerability could potentially lead to unauthorized control over the affected systems, posing significant risks to data security and operational integrity.

References

EPSS Score

46% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.