Impact
The vulnerabilities reside in several components of the HPLIP software stack and are capable of triggering a range of serious effects. They can allow an attacker to execute arbitrary code, elevate privileges, cause denial of service, disclose information, or modify files that should be protected. The presence of a buffer overflow weakness (CWE‑122) and an unauthorized file modification vulnerability (CWE‑494) implies that unsafe handling of external input or insufficient access checks are the root causes.
Affected Systems
HP Inc. HP Linux Imaging and Printing Software, which runs on Linux platforms. The CVE does not list specific release numbers, indicating that multiple components across the distribution are affected.
Risk and Exploitability
The CVSS score of 8.6 classifies the problem as high severity, while an EPSS of less than 1 % suggests that a widespread exploitation is currently unlikely. The issue is not listed in CISA’s KEV catalog. Attackers would most likely need to interact with HPLIP services or provide malicious input through a remote interface, exploiting the identified weaknesses to achieve code execution or privilege escalation.
OpenCVE Enrichment