PT-2023-2477 · Hewlett Packard · Hp Laserjet Managed Printers+2

Published

2023-04-03

·

Updated

2025-01-03

·

CVE-2023-1707

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions HP Enterprise LaserJet and HP LaserJet Managed Printers versions with FutureSmart version 5.6
Description The issue is related to a lack of protection for service data, potentially allowing a remote attacker to disclose protected information when IPsec is enabled. The problem may lead to information disclosure between printers and other devices in the network under certain conditions. It is estimated that around 50 models of premium HP Enterprise LaserJet and HP LaserJet Managed printers are affected. There have been no reported active exploitations, but given the high severity rating, it is likely that hackers will develop an exploit within a short period.
Recommendations For HP Enterprise LaserJet and HP LaserJet Managed Printers with FutureSmart version 5.6, consider downgrading to FutureSmart version 5.5.0.3 as a temporary mitigation measure until an update is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2023-02268
CVE-2023-1707

Affected Products

Futuresmart
Hp Laserjet Enterprise
Hp Laserjet Managed Printers