Risk | Low |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2022-24292 CVE-2022-24293 CVE-2022-24291 |
CWE-ID | CWE-125 CWE-121 CWE-119 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
HP Color LaserJet Pro MFP M2XX Hardware solutions / Office equipment, IP-phones, print servers HP Color LaserJet Pro M453 - M454 Hardware solutions / Office equipment, IP-phones, print servers HP Color LaserJet Pro MFP M478 Hardware solutions / Office equipment, IP-phones, print servers HP Color LaserJet Pro MFP M479 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro M304 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro M305 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro M404 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro M405 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro MFP M428 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro MFP M429 Hardware solutions / Office equipment, IP-phones, print servers HP LaserJet Pro MFP M429 F Hardware solutions / Office equipment, IP-phones, print servers HP PageWide 352dw Printer Hardware solutions / Office equipment, IP-phones, print servers HP PageWide 377dw Multifunction Printer Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Managed P55250dw Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Managed P57750dw Multifunction Printer Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 452dn Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 452dw Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 477dn Multifunction Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 477dw Multifunction Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 552dw Printer series Hardware solutions / Office equipment, IP-phones, print servers HP PageWide Pro 577 Multifunction Printer series Hardware solutions / Office equipment, IP-phones, print servers HP OfficeJet Pro 8210 Printer series Hardware solutions / Office equipment, IP-phones, print servers HP OfficeJet Pro 8216 Printer series Hardware solutions / Office equipment, IP-phones, print servers HP OfficeJet Pro 8730 All-in-One Printer Hardware solutions / Office equipment, IP-phones, print servers HP OfficeJet Pro 8740 All-in-One Printer series Hardware solutions / Office equipment, IP-phones, print servers |
Vendor | HP Development Company |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU61595
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-24292
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the PostScript interpreter. A remote attacker on the local network can trigger out-of-bounds read error and read contents of memory on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsHP Color LaserJet Pro MFP M2XX: All versions
HP Color LaserJet Pro M453 - M454: All versions
HP Color LaserJet Pro MFP M478: All versions
HP Color LaserJet Pro MFP M479: All versions
HP LaserJet Pro M304: All versions
HP LaserJet Pro M305: All versions
HP LaserJet Pro M404: All versions
HP LaserJet Pro M405: All versions
HP LaserJet Pro MFP M428: All versions
HP LaserJet Pro MFP M429: All versions
HP LaserJet Pro MFP M429 F: All versions
HP PageWide 352dw Printer: All versions
HP PageWide 377dw Multifunction Printer: All versions
HP PageWide Managed P55250dw Printer series: All versions
HP PageWide Managed P57750dw Multifunction Printer: All versions
HP PageWide Pro 452dn Printer series: All versions
HP PageWide Pro 452dw Printer series: All versions
HP PageWide Pro 477dn Multifunction Printer series: All versions
HP PageWide Pro 477dw Multifunction Printer series: All versions
HP PageWide Pro 552dw Printer series: All versions
HP PageWide Pro 577 Multifunction Printer series: All versions
HP OfficeJet Pro 8210 Printer series: All versions
HP OfficeJet Pro 8216 Printer series: All versions
HP OfficeJet Pro 8730 All-in-One Printer: All versions
HP OfficeJet Pro 8740 All-in-One Printer series: All versions
CPE2.3https://support.hp.com/us-en/document/ish_5950417-5950443-16
https://www.zerodayinitiative.com/advisories/ZDI-22-535/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU61597
Risk: Low
CVSSv4.0: 6.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-24293
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the eContactRestore within the address book feature. A remote user on the local network can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsHP Color LaserJet Pro MFP M2XX: All versions
HP Color LaserJet Pro M453 - M454: All versions
HP Color LaserJet Pro MFP M478: All versions
HP Color LaserJet Pro MFP M479: All versions
HP LaserJet Pro M304: All versions
HP LaserJet Pro M305: All versions
HP LaserJet Pro M404: All versions
HP LaserJet Pro M405: All versions
HP LaserJet Pro MFP M428: All versions
HP LaserJet Pro MFP M429: All versions
HP LaserJet Pro MFP M429 F: All versions
HP PageWide 352dw Printer: All versions
HP PageWide 377dw Multifunction Printer: All versions
HP PageWide Managed P55250dw Printer series: All versions
HP PageWide Managed P57750dw Multifunction Printer: All versions
HP PageWide Pro 452dn Printer series: All versions
HP PageWide Pro 452dw Printer series: All versions
HP PageWide Pro 477dn Multifunction Printer series: All versions
HP PageWide Pro 477dw Multifunction Printer series: All versions
HP PageWide Pro 552dw Printer series: All versions
HP PageWide Pro 577 Multifunction Printer series: All versions
HP OfficeJet Pro 8210 Printer series: All versions
HP OfficeJet Pro 8216 Printer series: All versions
HP OfficeJet Pro 8730 All-in-One Printer: All versions
HP OfficeJet Pro 8740 All-in-One Printer series: All versions
CPE2.3https://support.hp.com/us-en/document/ish_5950417-5950443-16
https://www.zerodayinitiative.com/advisories/ZDI-22-533/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU61596
Risk: Low
CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-24291
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the ScanJobs API. A remote attacker on the local network can trigger memory corruption and cause a denial of service condition on the target system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsHP Color LaserJet Pro MFP M2XX: All versions
HP Color LaserJet Pro M453 - M454: All versions
HP Color LaserJet Pro MFP M478: All versions
HP Color LaserJet Pro MFP M479: All versions
HP LaserJet Pro M304: All versions
HP LaserJet Pro M305: All versions
HP LaserJet Pro M404: All versions
HP LaserJet Pro M405: All versions
HP LaserJet Pro MFP M428: All versions
HP LaserJet Pro MFP M429: All versions
HP LaserJet Pro MFP M429 F: All versions
HP PageWide 352dw Printer: All versions
HP PageWide 377dw Multifunction Printer: All versions
HP PageWide Managed P55250dw Printer series: All versions
HP PageWide Managed P57750dw Multifunction Printer: All versions
HP PageWide Pro 452dn Printer series: All versions
HP PageWide Pro 452dw Printer series: All versions
HP PageWide Pro 477dn Multifunction Printer series: All versions
HP PageWide Pro 477dw Multifunction Printer series: All versions
HP PageWide Pro 552dw Printer series: All versions
HP PageWide Pro 577 Multifunction Printer series: All versions
HP OfficeJet Pro 8210 Printer series: All versions
HP OfficeJet Pro 8216 Printer series: All versions
HP OfficeJet Pro 8730 All-in-One Printer: All versions
HP OfficeJet Pro 8740 All-in-One Printer series: All versions
CPE2.3https://support.hp.com/us-en/document/ish_5950417-5950443-16
https://www.zerodayinitiative.com/advisories/ZDI-22-534/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.