SMTP Credential Exposure Vulnerability in HP DesignJet and Latex Printers
CVE-2017-2747
7.8HIGH
Key Information:
- Vendor
- HP
- Vendor
- CVE Published:
- 23 January 2018
Summary
HP has identified a vulnerability in certain DesignJet and Latex printers that may expose the credentials of the configured SMTP server. This potential security flaw can lead to unauthorized access to email communications handled by the printers, increasing the risk of data breaches. The issue affects various models across both the DesignJet and Latex product lines, prompting users to implement recommended security measures to protect sensitive information.
Affected Version(s)
HP Designjet printers; HP Latex printers fixed in IG_11_00_00.10, MRY_04_05_00.5, and AENEAS_03_04_00.9
HP Designjet printers; HP Latex printers NEXUS_01_12_00.11, NEXUS_03_12_00.15, and STORM_00_05_01.6
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved