Impact
HP has identified multiple vulnerabilities in the Linux Imaging and Printing Software (HPLIP) that could lead to remote code execution, privilege escalation, denial of service, information disclosure or unauthorized file modification under certain conditions. Each flaw resides in different components of the application and together create a small but real risk for attackers who can trigger the affected code paths. The consequence of exploitation includes potential full control of the affected system, loss of confidentiality, integrity or availability, and the ability to alter or delete system files.
Affected Systems
The only affected product listed is HP Linux Imaging and Printing Software (HPLIP) provided by HP Inc. No specific version numbers are attached to the report, meaning all released releases of the software may need to be considered at risk until HP confirms supported fixes.
Risk and Exploitability
The CVSS score of 5.1 reflects the moderate severity of the overall vulnerability bundle, and the EPSS score of less than 1 % indicates a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited widespread exploitation. The likely attack vector is remote, inferred from the description of "remote code execution" and "external reporting". An attacker would need to manipulate or coerce HPLIP, presumably via a network-exposed service or an operating system component that invokes HPLIP functions, to trigger the flaws.
OpenCVE Enrichment