Impact
Multiple externally reported weaknesses in HP Linux Imaging and Printing Software (HPLIP) could allow a remote attacker to execute arbitrary code, elevate privileges, disrupt service availability, disclose sensitive data, or modify files. The underlying flaw is characterized as a buffer overflow (CWE-122), which can be exploited when the software processes untrusted input. If leveraged, an attacker could compromise the local system and gain full control over the affected machine.
Affected Systems
The vulnerabilities affect HP Linux Imaging and Printing Software (HPLIP) distributed by HP Inc. The data does not specify exact product versions; therefore the potential impact applies to all installations of HPLIP that include the vulnerable components. Users should verify whether their version of HPLIP includes the identified fixes.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity critical flaw, while the EPSS score of less than 1% suggests a low probability of near‑term exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network interactions such as print service requests or related protocols, allowing an attacker to deliver malicious payloads to an unpatched system. The combination of remote exploitation potential and high impact warrants urgent attention.
OpenCVE Enrichment