2023-04-28 20:00:26 +02:00
{
"id" : "CVE-2023-1526" ,
"sourceIdentifier" : "hp-security-alert@hp.com" ,
"published" : "2023-04-28T17:15:42.973" ,
2023-05-10 20:00:27 +02:00
"lastModified" : "2023-05-10T16:47:44.507" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-28 20:00:26 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer."
}
] ,
2023-05-10 20:00:27 +02:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "PHYSICAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.6 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 0.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:designjet_z6:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3AC21A58-00BA-4EDF-9EF0-870AE44D218B"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:designjet_z6_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "jgr6_09_22_51.2" ,
"matchCriteriaId" : "79275045-E680-4980-AE2E-E4B4FF2F9EF9"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:designjet_z6dr:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9830F6D2-A1EF-48D9-A9FE-EF4F3CC37A9C"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:designjet_z6dr_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "jgr6_09_22_51.2" ,
"matchCriteriaId" : "D98922E6-9D13-499C-BD28-E6FE2BC60327"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:designjet_z9:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E8876C93-02EA-4AB0-BD3E-E73C5293BD74"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:designjet_z9_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "jgr9_09_22_51.2" ,
"matchCriteriaId" : "DF1E5F8A-53F4-4575-B647-21FE43BD81D6"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:designjet_z9dr:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "944C8DAB-1262-4D78-943E-BE43FCA7AF86"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:designjet_z9dr_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "jgr9_09_22_51.2" ,
"matchCriteriaId" : "FBB204FE-BCF4-49E4-B86B-D8DAC3B65174"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:designjet_z9\\+_pro:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3B5271B-CA09-45EB-BE82-5573E15BCB7B"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:designjet_z9\\+_pro_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C5038AB0-6D73-4CC3-9790-82BADDBF48A2"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:pagewide_xl_4700:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD7EFD29-61E5-44DD-BF9E-E7A94C7518D3"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:pagewide_xl_4700:_firmware:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "9E35992F-797A-4210-AD84-B73119A8119D"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:pagewide_xl_4500:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C79CA733-FC8F-409E-B7F5-17C62C352C07"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:pagewide_xl_4500:_firmware:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "59D4C8D4-634D-4328-BADA-586D0DB774B5"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:pagewide_xl_4100:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8176BFFE-C208-4E5C-9D68-666A747D84B2"
2023-05-10 20:00:27 +02:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:pagewide_xl_4100:_firmware:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "F336F37C-C59F-48C4-884A-6EEFE2CEDBAE"
2023-05-10 20:00:27 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:pagewide_xl_4600:_firmware:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "8D0C17BB-2F0F-4AD9-9C53-BE5F07D4817A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:pagewide_xl_4600:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4B438074-4FBD-4167-8B49-E632088108B1"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:hp:pagewide_xl_8000:_firmware:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "724920B8-F956-457F-9CBF-0F0620AC4630"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:pagewide_xl_8000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E9889CAC-98CE-48D8-B49B-BAB37CC8AFC2"
}
]
}
]
}
] ,
2023-04-28 20:00:26 +02:00
"references" : [
{
"url" : "https://support.hp.com/us-en/document/ish_7869666-7869691-16/hpsbpi03837" ,
2023-05-10 20:00:27 +02:00
"source" : "hp-security-alert@hp.com" ,
"tags" : [
"Vendor Advisory"
]
2023-04-28 20:00:26 +02:00
}
]
}