PT-2023-25185 · Hewlett Packard · Hp Laserjet Pro

Published

2023-06-30

·

Updated

2023-08-24

·

CVE-2023-35175

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HP LaserJet Pro print products (affected versions not specified)
Description The issue concerns a potential remote code execution and/or elevation of privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model. This could potentially affect certain HP LaserJet Pro print products. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-35175
ZDI-23-1171
ZDI-23-1174

Affected Products

Hp Laserjet Pro