Hundreds Of HP Printer models Vulnerable To 3 Critical Flaws

Share post:

HP has issued warnings on three critical-severity flaws affecting hundreds of the company’s printer models.

The models include LaserJet Pro, Pagewide Pro, OfficeJet, Enterprise, Large Format, and DeskJet.

The three flaws include two critical and one high-severity vulnerability. The three flaws could be exploited for information disclosure, remote code execution, and denial of service.

The three vulnerabilities are tracked as CVE-2022-24291, a high severity flaw that comes with a CVSS score of 7.5, CVE-2022-24292, a critical severity flaw with a CVSS score of 9.8, and CVE-2022-24293, a critical severity flaw with a 9.8 CVSS rating.

Admins are advised to update their printer firmware to the designated versions. However, this is flawed since it isn’t available for all impacted models.

While there is no mitigation for one of the listed LaserJet Pro models, other models admins can mitigate the issue by installing the latest available firmware version on HP’s official software portal.

For more information, read the original story in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for Friday, December 1, 2023

This episode features a discussion on ransomware, the latest explanation from Okta of a support hack and a survey of infosec pros whose firms w

Cyber Security Today, Dec. 1, 2023 podcast – More on Booking.com compromises

This episode reports on the sanctioning of the Sinbad crypto mixe

All Okta customer support users had their email addresses copied

Identity and access provider Okta now says the threat actor who accessed its customer help desk system last month got the names and email addresses of all contacts of organizations that use its support system. Originally, the company said that, after an investigation, it determined only one per cent of the contacts from its 18,000

Failure of technology to detect attacks is a prime cause of breaches: Survey

Despite the money being poured into cybersecurity by IT departments, the leading cause of breaches of security controls was the failure of technology to detect an attack, a new survey from Trellix suggests. Forty-two per cent of respondents to the international survey of infosec leaders whose organization had suffered a recent cyber attack said their

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways