A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability
could potentially allow a local attacker to escalate privileges via a race condition when installing packages.

Project Subscriptions

Vendors Products
Image Assistant Subscribe
Hp Image Assistant Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 06 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp image Assistant
CPEs cpe:2.3:a:hp:image_assistant:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp image Assistant
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 03 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.
Title HP Image Assistant - Potential Escalation of Privilege
First Time appeared Hp Inc
Hp Inc hp Image Assistant
Weaknesses CWE-363
CPEs cpe:2.3:a:hp_inc:hp_image_assistant:*:*:*:*:*:*:*:*
Vendors & Products Hp Inc
Hp Inc hp Image Assistant
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2025-12-04T04:55:15.971Z

Reserved: 2025-11-20T21:13:55.431Z

Link: CVE-2025-13492

cve-icon Vulnrichment

Updated: 2025-12-03T16:51:46.615Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-03T17:15:49.733

Modified: 2025-12-05T23:51:25.677

Link: CVE-2025-13492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses