Your HP printer could be facing the risk of a serious cyberattack

Image depicting a hand on a scanner
Image Credit: Pixabay (Image credit: Pixabay)

HP has issued patches for four dangerous vulnerabilities affecting hundreds of its printers. According to two security advisories that the company published, the vulnerabilities could lead to remote code execution, data theft, or denial of service.

The models affected by the flaws include the likes of the LaserJet Pro series, Pagewide Pro series, OfficeJet, Enterprise, Large Format, and DeskJet. 

The first issue is tracked as CVE-2022-3942. It comes with an 8.4 severity score, which would rank it as “high severity”, but HP tracks it as “critical”.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Not all devices have patches

“Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with the use of Link-Local Multicast Name Resolution or LLMNR.” the company said in one of the advisories.

The second advisory discusses three additional flaws, two of which are described as “critical” and one as “high severity”. These could lead to remote code execution, denial of service, or information exfiltration.

Tracked as CVE-2022-24291, CVE-2022-24292, and CVE-2022-24293, these can also be addressed by updating the device firmware. 

HP endpoint admins interested in updating their devices should visit HP’s official software and driver download portal, to look for the appropriate fix. 

The bad news is that HP did not prepare firmware updates for all of the affected devices, but it did offer workarounds. Most of them include disabling LLMNR (Link-Local Multicast Name Resolution) in network settings. 

Those interested in disabling unused network protocols via embedded web server for LasterJet Pro should check out more details here. Those with other devices should refer to the guidelines on this link. 

These are high-severity risks, which could potentially be abused with malware for remote code execution. As such, they are too risky not to be addressed, and admins should move fast to plug these holes as soon as possible.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Digital image of a lock.
Xerox printer security risk could let hackers sneak into your systems
HP LaserJet Pro 3000 on modern office desk
Now HP printers are being bricked following firmware update
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
cables going into the back of a broadband router on white background
Netgear urges users to patch major router security issues now
Latest in Security
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
Latest in News
UK Prime Minister Sir Kier Starmer
UK PM says AI should soon replace civil servants
Eight Samsung TVs mounted to the wall showing different basketball games
Samsung is offering you 8 new TVs in one bundle for March Madness, in case you want to watch all games at once like a Bond villain’s lair
The Steam Logo on a mobile phone in front of a wall of games.
Today’s Steam Spring Sale features my absolute favorite game of all time - here's when the sale starts and all the key info
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Half-Life running on a smartwatch
This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Life
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade