Impact
HP identified multiple externally reported issues affecting the HPLIP software that could enable remote code execution, privilege escalation, denial‑of‑service, information disclosure, or unauthorized file modification. These vulnerabilities affect several components of HPLIP, yet the CVE does not outline a specific exploitation path. The potential impact includes compromising confidentiality, integrity, or availability for Linux systems that run HPLIP.
Affected Systems
The affected product is HP Linux Imaging and Printing Software (HPLIP) for Linux. No specific version range is listed, so any installation of HPLIP that has not yet been patched by HP is potentially vulnerable. HP Inc. is the sole vendor identified as impacted.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity risk. The EPSS score is below 1 %, suggesting a very low probability of exploitation at the time of the analysis, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is external; an attacker could send crafted payloads or requests to a vulnerable HPLIP component from an untrusted network or local user context. In the absence of a publicly posted exploit and with the low EPSS, the immediate threat is moderate, but the high CVSS warrants remediation.
OpenCVE Enrichment