Impact
HP has identified multiple externally reported vulnerabilities within the HP Linux Imaging and Printing Software (HPLIP). The affected components could enable an attacker to execute arbitrary code on the target system, elevate privileges, disrupt service availability, disclose sensitive information, or modify files without authorization. The weaknesses are consistent with a heap‑based buffer overflow (CWE‑122) and weak cryptographic key management (CWE‑266).
Affected Systems
The vulnerabilities affect the HP Inc. HP Linux Imaging and Printing Software (HPLIP) for Linux systems. Specific version information was not disclosed in the public advisory, so all current releases of HPLIP that include the affected components are potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, but the EPSS score of less than 1% shows that exploitation is currently unlikely. HPLIP is not listed in CISA’s KEV catalog, further suggesting a lower exploitation probability. The likely attack vector is remote, possibly via uncovered network interfaces or removable media inputs that interact with HPLIP’s printing services. System administrators should treat this as a serious threat, prioritizing patching when one becomes available.
OpenCVE Enrichment