Impact
HP identified several vulnerabilities in HPLIP that could allow an attacker to execute code on the system, elevate privileges, crash the service, or read and modify sensitive files. The weaknesses involve integer overflows and insufficient access controls, which are listed as CWE-191 and CWE-266. The potential damage ranges from full system compromise to data disclosure and denial of service.
Affected Systems
The affected product is HP Linux Imaging and Printing Software (HPLIP) from HP Inc. No specific version range is supplied in the CVE record, so all installed instances of HPLIP may be at risk until updated.
Risk and Exploitability
With a CVSS score of 5.1 and an EPSS score below 1%, the likelihood of widespread exploitation is currently low. The vulnerabilities are not yet in CISA’s KEV catalog. Because the issues are externally reported and could be triggered from a networked printer interface, the probable attack vector is remote, although local users or privileged accounts could also exploit the flaws depending on the exact component affected.
OpenCVE Enrichment