SMTP Credential Exposure Vulnerability in HP DesignJet and Latex Printers
CVE-2017-2747

7.8HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
23 January 2018

Summary

HP has identified a vulnerability in certain DesignJet and Latex printers that may expose the credentials of the configured SMTP server. This potential security flaw can lead to unauthorized access to email communications handled by the printers, increasing the risk of data breaches. The issue affects various models across both the DesignJet and Latex product lines, prompting users to implement recommended security measures to protect sensitive information.

Affected Version(s)

HP Designjet printers; HP Latex printers fixed in IG_11_00_00.10, MRY_04_05_00.5, and AENEAS_03_04_00.9

HP Designjet printers; HP Latex printers NEXUS_01_12_00.11, NEXUS_03_12_00.15, and STORM_00_05_01.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.