Site icon TheCyberThrone

HP LaserJet Printers has a Critical Bug

Advertisements

HP has issued a warning to its business customers using certain LaserJet printer models that they should remain vigilant and take steps to tackle a vulnerability that could see unwanted information disclosure occur.

The vulnerability tracked as CVE-2023-1707 with a CVSS score of 9.1, making it of critical severity.

As per HP statement, Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6.

Advertisements

HP has announced plans to issue a firmware update within 90 days, advising customers to downgrade firmware in the meantime to prevent unwanted attacks.

The company confirmed that affected customers are running FutureSmart 5.6, software designed to enable printer configuration from the control panel or a dedicated web page. Affected users will also have IPsec enabled.

A temporary downgrade to version 5.5.0.3 of the firmware for a period of up to three months while HP works on a fix.

Advertisements

Affected Devices

Exit mobile version