Impact
A flaw in HP Advance software may allow an attacker to gain elevated privileges, execute code remotely, or write arbitrary files on the HP Advance server that hosts the application. The vulnerability is classified with a CVSS score of 8.8, indicating high severity. The EPSS score is below 1 %, meaning the probability of exploitation observed in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote interaction with the HP Advance web interface; the attacker would need to target the server under conditions that enable the flaw to trigger. The consequences for confidentiality, integrity, or availability would be system‑wide if the vulnerability is exploited, as it could allow execution of arbitrary code and modification of critical files on the server.
Affected Systems
HP Inc products HP AC Print & Scan and HP Output Central are impacted when they run the HP Advance software. No specific version numbers are supplied in the data, so any installation of the HP Advance component that is located on a server may be susceptible.
Risk and Exploitability
The high CVSS score of 8.8 reflects serious privilege escalation and remote code execution potential. The EPSS score of less than 1 % indicates that real‑world exploitation is rare but possible. Since the issue is not currently in the KEV catalog, there have been no publicly confirmed exploits, but the presence of a remote code execution pathway means that an attacker who can reach the HP Advance server could potentially compromise the entire system. The lack of an official patch in the available data suggests that users must be proactive in checking for updates from HP and consider compensating controls until a fix is released.
OpenCVE Enrichment