Impact
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The weaknesses are tied to improper privilege management (CWE-266) and operating‑system command injection (CWE-78).
Affected Systems
The affected product is HP Linux Imaging and Printing Software (HPLIP) for Linux. No specific version ranges are listed, so any installation of HPLIP may be impacted until the vendor releases a fixed build.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, while an EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, further indicating that documented exploitation is not widespread as of this assessment. The likely attack vector is remote, as the issues allow code execution from outside the local system, implying that network‑exposed HPLIP services could be targeted. This risk is mitigated by applying vendor fixes and securing service exposure.
OpenCVE Enrichment