Vulnerabilidades em HP Inc.

158 resultados
Análise Vexday

O portfólio de vulnerabilidades da HP Inc. reúne 143 CVEs catalogadas, com 15 classificadas como críticas e nenhuma atualmente confirmada em exploração ativa no catálogo CISA KEV — desempenho abaixo da média geral do catálogo. Ainda assim, a CVE-2017-2741 exige atenção prioritária: embora não esteja no KEV, seu índice EPSS de 0,8489 indica alta probabilidade de exploração, tornando-a o risco mais imediato a ser tratado. O tipo de falha mais recorrente é CWE-269 (gerenciamento impróprio de privilégios), o que sugere fragilidades em controles de acesso que, se exploradas em cadeia, podem elevar o impacto de vulnerabilidades menos severas individualmente. A presença de apenas uma CVE com PoC pública e quatro surgidas nos últimos 90 dias indica um volume recente moderado, mas o monitoramento contínuo permanece necessário dado o perfil de risco da falha mais crítica identificada.

CVE-2024-3281HIGHA vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build EPSS 0.5%CVE-2025-2268MEDIUMHP LaserJet MFP M232-M237 Printer Series - Potential Denial of ServiceEPSS 0.5%CVE-2023-35176Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Denial of Service when using the backup & restorEPSS 0.4%CVE-2025-1004MEDIUMCertain HP LaserJet Pro Printers – Potential Denial of ServiceEPSS 0.4%CVE-2022-38396HIGHHP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions might allow escalation EPSS 0.4%CVE-2024-5143MEDIUMA user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server EPSS 0.4%CVE-2023-35178Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow when performing a GET request to scan jobs.EPSS 0.4%CVE-2026-5922MEDIUMPoly Voice – Potential Unauthorized Modification of WebUI using XSS AttackEPSS 0.4%CVE-2023-35177Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parserEPSS 0.4%CVE-2023-5113Certain HP Enterprise LaserJet, LaserJet Managed printers - Potential denial of service, potential Cross Site Scripting (XSS)EPSS 0.3%CVE-2024-0407MEDIUMCertain HP Enterprise LaserJet, HP LaserJet Managed Printers – Potential Information DisclosureEPSS 0.3%CVE-2026-91099MEDIUMHP Linux Imaging and Printing (HPLIP) Software– Multiple VulnerabilitiesEPSS 0.3%CVE-2025-10568MEDIUMHyperX NGENUITY - Arbitrary Code ExecutionEPSS 0.3%CVE-2025-43022HIGHPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.3%CVE-2021-3661HIGHA potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code executiEPSS 0.3%CVE-2022-27537HIGHPotential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escEPSS 0.3%CVE-2026-12553HIGHHP Web Jetadmin (WJA) - Potential Arbitrary File Read/WriteEPSS 0.3%CVE-2024-2301HIGHCertain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management interface of the deEPSS 0.3%CVE-2023-5409HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack,EPSS 0.3%CVE-2026-91101MEDIUMHP Linux Imaging and Printing (HPLIP) Software– Multiple VulnerabilitiesEPSS 0.3%