Impact
HP identified multiple externally reported vulnerabilities in the HPLIP package. The flaws affect several components and could allow an attacker to execute arbitrary code on a faulty system, elevate privileges, crash the application, steal confidential information, or modify files without authorization. The weaknesses include a classic off‑by‑one or buffer overrun (CWE‑787) and a code‑execution or command injection (CWE‑94).
Affected Systems
The affected product is HP Linux Imaging and Printing Software (HPLIP) distributed by HP Inc. The specific version numbers that contain the flaw were not disclosed in the advisory, but any installation of HPLIP prior to the vendor’s latest release should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7 reflects a high‑severity risk. The EPSS score of less than 1 % indicates a low probability that the vulnerability will be actively exploited at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the likely attack vector is remote, as the flaw involves components that interface over the network or accept external input. If abused, an attacker could gain a local or remote foothold, persist on the host, or disrupt printing services for users.
OpenCVE Enrichment