Impact
HP Advance software contains a code injection flaw that can lead to a wide range of security breaches, including elevation of privilege, remote code execution, and arbitrary file write on the HP Advance server. The weakness is a classic code execution vulnerability. An attacker who can influence the problematic input would be able to run arbitrary commands, gain administrative rights, and modify or create files on the server, potentially compromising sensitive data or the integrity of the entire printing and scanning infrastructure.
Affected Systems
The affected systems are the HP Advance server that hosts the HP AC Print & Scan and HP Output Central applications. No specific affected firmware or software versions are listed, so all installations of HP Advance are presumed at risk until a vendor‑issued fix is applied.
Risk and Exploitability
The base CVSS score of 9.3 indicates a high‑severity threat. The EPSS score is reported as less than 1%, which suggests that exploitation in the wild has not yet been widely observed, although the low probability does not eliminate risk. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, requiring the ability to deliver crafted input to the HP Advance server, for example through exposed network services or web interfaces. Once exploited, the attacker obtains core system capabilities.
OpenCVE Enrichment