
HP has issued a warning to its business customers using certain LaserJet printer models that they should remain vigilant and take steps to tackle a vulnerability that could see unwanted information disclosure occur.
The vulnerability tracked as CVE-2023-1707 with a CVSS score of 9.1, making it of critical severity.
As per HP statement, Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.
HP has announced plans to issue a firmware update within 90 days, advising customers to downgrade firmware in the meantime to prevent unwanted attacks.
The company confirmed that affected customers are running FutureSmart 5.6, software designed to enable printer configuration from the control panel or a dedicated web page. Affected users will also have IPsec enabled.
A temporary downgrade to version 5.5.0.3 of the firmware for a period of up to three months while HP works on a fix.
Affected Devices
- HP Color LaserJet Enterprise M455
- HP Color LaserJet Enterprise MFP M480
- HP Color LaserJet Managed E45028
- HP Color LaserJet Managed MFP E47528
- HP Color LaserJet Managed MFP E785dn, HP Color LaserJet Managed MFP E78523, E78528
- HP Color LaserJet Managed MFP E786, HP Color LaserJet Managed Flow MFP E786, HP Color LaserJet Managed MFP E78625/30/35, HP Color LaserJet Managed Flow MFP E78625/30/35
- HP Color LaserJet Managed MFP E877, E87740/50/60/70, HP Color LaserJet Managed Flow E87740/50/60/70
- HP LaserJet Enterprise M406
- HP LaserJet Enterprise M407
- HP LaserJet Enterprise MFP M430
- HP LaserJet Enterprise MFP M431
- HP LaserJet Managed E40040
- HP LaserJet Managed MFP E42540
- HP LaserJet Managed MFP E730, HP LaserJet Managed MFP E73025, E73030
- HP LaserJet Managed MFP E731, HP LaserJet Managed Flow MFP M731, HP LaserJet Managed MFP E73130/35/40, HP LaserJet Managed Flow MFP E73130/35/40
- HP LaserJet Managed MFP E826dn, HP LaserJet Managed Flow MFP E826z, HP LaserJet Managed E82650/60/70, HP LaserJet Managed E82650/60/70