QID 730783

Date Published: 2023-04-12

QID 730783: HP Printers Information Disclosure Vulnerability

Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.

Affected Products:
HP LaserJet Managed E40040 3PZ35A firmware version prior to FS5: 5.5.0.3 (2505701_000839)
HP LaserJet Enterprise M406 3PZ15A firmware version prior to FS5: 5.5.0.3 (2505701_000839)
HP LaserJet Enterprise MFP M430 3PZ55A firmware version prior to FS5: 5.5.0.3 (2505701_000834)
HP LaserJet Managed MFP E42540 3PZ75A firmware version prior to FS5: 5.5.0.3 (2505701_000834)
HP Color LaserJet Managed MFP E47528 3QA75A firmware version prior to FS5: 5.5.0.3 (2505701_000855)
HP Color LaserJet Enterprise MFP M480 3QA55A firmware version prior to FS5: 5.5.0.3 (2505701_000855)
HP Color LaserJet MFP E78625 5QJ90A firmware version prior to FS5: 5.5.0.3 (2505701_000849)
HP Color LaserJet Enterprise M455 3PZ95A firmware version prior to FS5: 5.5.0.3 (2505701_000841)

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of HP Printer by sending a GET request to /hp/device/InternalPages/Index?id=ConfigurationPage endpoint.

Successful exploitation of the vulnerability may result in information disclosure.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Please refer to HPSBPI03838 for patch information.

    Workaround:
    HP has provided a temporary firmware mitigation for customers currently running FutureSmart 5.6 with IPsec enabled on potentially impacted products. HP recommends immediately reverting to a prior version of the firmware (FutureSmart version 5.5.0.3).

    CVEs related to QID 730783

    Software Advisories
    Advisory ID Software Component Link
    HPSBPI03838 URL Logo support.hp.com/us-en/document/ish_7905330-7905358-16/hpsbpi03838