Buffer Overflow Vulnerability in OpenPrinting ippusbxd Product by OpenPrinting
CVE-2024-45062
6.4MEDIUM
What is CVE-2024-45062?
A buffer overflow vulnerability exists within the OpenPrinting ippusbxd version 1.34, which may be exploited when a specially configured printer using IPP-over-USB is connected to the system. This configuration can lead to arbitrary code execution in a privileged service, posing significant risks if a malicious device is attached via USB. Users are advised to ensure only trusted devices are connected and to monitor their systems for unauthorized access.
Affected Version(s)
ippusbxd 1.34
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Aleksandar Nikolic of Cisco Talos.