CVE-2017-2741
| Summary |
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.
|
| Publication Date |
Jan. 24, 2018, 1:29 a.m. |
| Registration Date |
Jan. 26, 2021, 1:22 p.m. |
| Last Update |
Nov. 21, 2024, 12:24 p.m. |
|
CVSS3.0 : CRITICAL
|
| スコア |
9.8
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃に必要な特権レベル(PR) |
不要 |
| 利用者の関与(UI) |
不要 |
| 影響の想定範囲(S) |
変更なし |
| 機密性への影響(C) |
高 |
| 完全性への影響(I) |
高 |
| 可用性への影響(A) |
高 |
|
CVSS2.0 : HIGH
|
| Score |
10.0
|
| Vector |
AV:N/AC:L/Au:N/C:C/I:C/A:C |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃前の認証要否(Au) |
不要 |
| 機密性への影響(C) |
高 |
| 完全性への影響(I) |
高 |
| 可用性への影響(A) |
高 |
| Get all privileges. |
いいえ
|
| Get user privileges |
いいえ
|
| Get other privileges |
いいえ
|
| User operation required |
いいえ
|
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v82a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v82a:-:*:*:*:*:*:*:* |
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v82b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v82b:-:*:*:*:*:*:*:* |
| Configuration3 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v82c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v82c:-:*:*:*:*:*:*:* |
| Configuration4 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v82d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v82d:-:*:*:*:*:*:*:* |
| Configuration5 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j6u55a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j6u55a:-:*:*:*:*:*:*:* |
| Configuration6 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j6u55b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j6u55b:-:*:*:*:*:*:*:* |
| Configuration7 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j6u55c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j6u55c:-:*:*:*:*:*:*:* |
| Configuration8 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j6u55d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j6u55d:-:*:*:*:*:*:*:* |
| Configuration9 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:k9z76a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:k9z76a:-:*:*:*:*:*:*:* |
| Configuration10 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:k9z76d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:k9z76d:-:*:*:*:*:*:*:* |
| Configuration11 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q17a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q17a:-:*:*:*:*:*:*:* |
| Configuration12 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q17c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q17c:-:*:*:*:*:*:*:* |
| Configuration13 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q17d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q17d:-:*:*:*:*:*:*:* |
| Configuration14 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q21a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q21a:-:*:*:*:*:*:*:* |
| Configuration15 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q21c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q21c:-:*:*:*:*:*:*:* |
| Configuration16 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q21d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q21d:-:*:*:*:*:*:*:* |
| Configuration17 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q20a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q20a:-:*:*:*:*:*:*:* |
| Configuration18 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q20b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q20b:-:*:*:*:*:*:*:* |
| Configuration19 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q20c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q20c:-:*:*:*:*:*:*:* |
| Configuration20 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q20d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q20d:-:*:*:*:*:*:*:* |
| Configuration21 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q16a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q16a:-:*:*:*:*:*:*:* |
| Configuration22 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q16b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q16b:-:*:*:*:*:*:*:* |
| Configuration23 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q16c_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q16c:-:*:*:*:*:*:*:* |
| Configuration24 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q16d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q16d:-:*:*:*:*:*:*:* |
| Configuration25 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q19a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q19a:-:*:*:*:*:*:*:* |
| Configuration26 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q19d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q19d:-:*:*:*:*:*:*:* |
| Configuration27 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q15a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q15a:-:*:*:*:*:*:*:* |
| Configuration28 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q15b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q15b:-:*:*:*:*:*:*:* |
| Configuration29 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d3q15d_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d3q15d:-:*:*:*:*:*:*:* |
| Configuration30 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v80a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v80a:-:*:*:*:*:*:*:* |
| Configuration31 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j9v80b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j9v80b:-:*:*:*:*:*:*:* |
| Configuration32 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j6u57b_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j6u57b:-:*:*:*:*:*:*:* |
| Configuration33 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d9l20a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d9l20a:-:*:*:*:*:*:*:* |
| Configuration34 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d9l21a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d9l21a:-:*:*:*:*:*:*:* |
| Configuration35 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d9l63a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d9l63a:-:*:*:*:*:*:*:* |
| Configuration36 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:d9l64a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:d9l64a:-:*:*:*:*:*:*:* |
| Configuration37 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:t0g70a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:t0g70a:-:*:*:*:*:*:*:* |
| Configuration38 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:hp:j3p68a_firmware:*:*:*:*:*:*:*:* |
|
|
|
1708d |
| execution environment |
| 1 |
cpe:2.3:h:hp:j3p68a:-:*:*:*:*:*:*:* |
Related information, measures and tools
Common Vulnerabilities List
JVN Vulnerability Information
HP PageWide プリンタおよび OfficeJet Pro プリンタのファームウェアにおけるアクセス制御に関する脆弱性
| Title |
HP PageWide プリンタおよび OfficeJet Pro プリンタのファームウェアにおけるアクセス制御に関する脆弱性
|
| Summary |
HP PageWide プリンタおよび OfficeJet Pro プリンタのファームウェアには、アクセス制御に関する脆弱性が存在します。
|
| Possible impacts |
情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
April 5, 2017, midnight |
| Registration Date |
Feb. 27, 2018, 4:13 p.m. |
| Last Update |
Feb. 27, 2018, 4:13 p.m. |
Affected System
| ヒューレット・パッカード |
|
D3Q17A ファームウェア 1708D 未満
|
|
D9L20A ファームウェア 1708D 未満
|
|
J3P68A ファームウェア 1708D 未満
|
|
J6U55A ファームウェア 1708D 未満
|
|
J6U57B ファームウェア 1708D 未満
|
|
J9V80A ファームウェア 1708D 未満
|
|
J9V82A ファームウェア 1708D 未満
|
|
K9Z76A ファームウェア 1708D 未満
|
|
T0G70A ファームウェア 1708D 未満
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2018年02月27日] 掲載 |
Feb. 27, 2018, 4:13 p.m. |