CVE-2018-5924
9.8
CRITICAL · CVSS 3.0 · EPSS 12.2% (pctl 96)
Patch early
EPSS 12.2% — above the 10% action threshold.
Description
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 12.23% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-08-13 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| hp | 1sh08 |
| hp | 1sh08 firmware |
| hp | 3aw44a |
| hp | 3aw44a firmware |
| hp | 3aw51a |
| hp | 3aw51a firmware |
| hp | 4uj28b |
| hp | 4uj28b firmware |
| hp | a9u19a |
| hp | a9u19a firmware |
| hp | a9u28b |
| hp | a9u28b firmware |
| hp | d3a78b |
| hp | d3a78b firmware |
| hp | d3a82a |
| hp | d3a82a firmware |
| hp | d4h22a |
| hp | d4h22a firmware |
| hp | d4h24b |
| hp | d4h24b firmware |
| hp | f5s57a |
| hp | f5s57a firmware |
| hp | j6u57b |
| hp | j6u57b firmware |
| hp | k4t99b |
| hp | k4t99b firmware |
| hp | k4u04b |
| hp | k4u04b firmware |
| hp | t8x39 |
| hp | t8x39 firmware |
| hp | t8x44 |
| hp | t8x44 firmware |
| hp | v1n01a |
| hp | v1n01a firmware |
| hp | v1n08a |
| hp | v1n08a firmware |
| hp | y5h60a |
| hp | y5h60a firmware |
| hp | y5h80a |
| hp | y5h80a firmware |
References
- http://www.securityfocus.com/bid/105010
- http://www.securitytracker.com/id/1041415
- https://research.checkpoint.com/sending-fax-back-to-the-dark-ages/
- https://support.hp.com/us-en/document/c06097712
- http://www.securityfocus.com/bid/105010
- http://www.securitytracker.com/id/1041415
- https://research.checkpoint.com/sending-fax-back-to-the-dark-ages/
- https://support.hp.com/us-en/document/c06097712
→ the Explorer · watch your stack · NVD