Impact
HP has identified multiple vulnerabilities in the HP Linux Imaging and Printing Software (HPLIP) that could enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The exact mechanisms are not detailed, but the potential to execute arbitrary code or modify files on the host is indicated.
Affected Systems
The affected vendor is HP Inc., with the product HP Linux Imaging and Printing Software (HPLIP). Specific affected versions are not listed in the available data, so organizations should ensure they are running the latest patched release of HPLIP.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low exploitation probability. The vulnerability is not listed in CISA KEV, reducing the likelihood of widespread exploitation. The attack vector is inferred to be remote, possibly involving malicious print jobs or network traffic, but the precise conditions remain unspecified.
OpenCVE Enrichment