Impact
The vulnerability in HP Advance software allows attackers to execute arbitrary code, elevate privileges, or write arbitrary files on the HP Advance server. This weakness is due to a command injection flaw (CWE-94) that can be triggered under specific conditions, enabling an attacker to compromise the server’s confidentiality, integrity, and availability. The impact includes full system compromise and unauthorized access to sensitive data.
Affected Systems
Affected vendors include HP Inc HP AC Print & Scan and HP Inc HP Output Central. The vulnerability impacts the HP Advance server software that hosts this functionality. No specific version information is available in the advisory.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical assessment of risk. The EPSS score of less than 1% shows a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as the bug can be triggered by interacting with the HP Advance server over the network; however, the exact mechanism was not detailed in the advisory and is therefore inferred.
OpenCVE Enrichment