CVE-2017-2747
Last modified
CVE-2017-2747 is a vulnerability of currently unknown severity. HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | T790 Firmware | <= ig_11_00_00.09 |
| Hp | T795 Firmware | <= ig_11_00_00.09 |
| Hp | T1300 Firmware | <= ig_11_00_00.09 |
| Hp | T2300 Firmware | <= ig_11_00_00.09 |
| Hp | T920 Firmware | <= mry_04_05_00.4 |
| Hp | T930 Firmware | <= mry_04_05_00.4 |
| Hp | T1500 Firmware | <= mry_04_05_00.4 |
| Hp | T1530 Firmware | <= mry_04_05_00.4 |
| Hp | T2500 Firmware | <= mry_04_05_00.4 |
| Hp | T2530 Firmware | <= mry_04_05_00.4 |
| Hp | T3500 Firmware | <= aeneas_03_04_00.8 |
| Hp | 110 Firmware | <= nexus_00_04_53.8 |
| Hp | 310 Firmware | <= nexus_01_12_00.10 |
| Hp | 330 Firmware | <= nexus_01_12_00.10 |
| Hp | 360 Firmware | <= nexus_01_12_00.10 |
| Hp | 370 Firmware | <= nexus_01_12_00.10 |
| Hp | 315 Firmware | <= nexus_03_12_00.14 |
| Hp | 335 Firmware | <= nexus_03_12_00.14 |
| Hp | 365 Firmware | <= nexus_03_12_00.14 |
| Hp | 375 Firmware | <= nexus_03_12_00.14 |
| Hp | 560 Firmware | <= storm_00_05_01.5 |
| Hp | 570 Firmware | <= storm_00_05_01.5 |
References
- https://support.hp.com/us-en/document/c05624457Vendor Advisory
- https://support.hp.com/us-en/document/c05624457Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2747?
How severe is CVE-2017-2747?
How do I fix CVE-2017-2747?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2741A potential security vulnerability has been identified with …
- CVE-2017-2742A potential security vulnerability has been identified with …
- CVE-2017-2743HP has identified a potential security vulnerability with HP…
- CVE-2017-2744The vulnerability allows attacker to extract binaries into p…
- CVE-2017-2745Potential security vulnerabilities have been identified with…
- CVE-2017-2746Potential security vulnerabilities have been identified with…
- CVE-2017-2748A potential security vulnerability caused by the use of inse…
- CVE-2017-2750Insufficient Solution DLL Signature Validation allows potent…
- CVE-2017-2751A BIOS password extraction vulnerability has been reported o…
- CVE-2017-2752A potential security vulnerability caused by incomplete obfu…
- CVE-2017-2765EMC Isilon InsightIQ 4.1.0, 4.0.1, 4.0.0, 3.2.2, 3.2.1, 3.2.…
- CVE-2017-2766EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom ver…
Are you affected by CVE-2017-2747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
