CVE-2021-3438

HIGHCVSS 7.8/10EPSS 2.90%

Last modified

CVE-2021-3438 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.. EPSS estimates a 2.90% chance of exploitation in the next 30 days.

Description

A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.90%

85.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpColor Laser 150 4zb94aAll versions
HpColor Laser 150 4zb95aAll versions
HpColor Laser Mfp 170 4zb96aAll versions
HpColor Laser Mfp 170 4zb97aAll versions
HpColor Laser Mfp 170 6hu08aAll versions
HpColor Laser Mfp 170 6hu09aAll versions
HpLaser 100 209u7aAll versions
HpLaser 100 4zb79aAll versions
HpLaser 100 4zb80aAll versions
HpLaser 100 4zb81aAll versions
HpLaser 100 5ue14aAll versions
HpLaser 408 7uq75aAll versions
HpLaser Mfp 130 4zb82aAll versions
HpLaser Mfp 130 4zb83aAll versions
HpLaser Mfp 130 4zb84aAll versions
HpLaser Mfp 130 4zb85aAll versions
HpLaser Mfp 130 4zb86aAll versions
HpLaser Mfp 130 4zb87aAll versions
HpLaser Mfp 130 4zb88aAll versions
HpLaser Mfp 130 4zb89aAll versions
HpLaser Mfp 130 4zb90aAll versions
HpLaser Mfp 130 4zb91aAll versions
HpLaser Mfp 130 4zb92aAll versions
HpLaser Mfp 130 4zb93aAll versions
HpLaser Mfp 130 5ue15aAll versions
HpLaser Mfp 130 6hu10aAll versions
HpLaser Mfp 130 6hu11aAll versions
HpLaser Mfp 130 6hu12aAll versions
HpLaser Mfp 130 9vv52aAll versions
HpLaser Mfp 432 7uq76aAll versions
HpLaserjet Mfp M42523 7ab26aAll versions
HpLaserjet Mfp M42523 7zb25aAll versions
HpLaserjet Mfp M42523 7zb72aAll versions
HpLaserjet Mfp M42625 8af49aAll versions
HpLaserjet Mfp M42625 8af50aAll versions
HpLaserjet Mfp M42625 8af51aAll versions
HpLaserjet Mfp M42625 8af52aAll versions
HpLaserjet Mfp M433 1vr14aAll versions
HpLaserjet Mfp M436 2ky38aAll versions
HpLaserjet Mfp M436 W7u01aAll versions
HpLaserjet Mfp M436 W7u02aAll versions
HpLaserjet Mfp M437 7zb19aAll versions
HpLaserjet Mfp M437 7zb20aAll versions
HpLaserjet Mfp M437 7zb21aAll versions
HpLaserjet Mfp M438 8af43aAll versions
HpLaserjet Mfp M438 8af44aAll versions
HpLaserjet Mfp M438 8af45aAll versions
HpLaserjet Mfp M439 7zb22aAll versions
HpLaserjet Mfp M439 7zb23aAll versions
HpLaserjet Mfp M439 7zb24aAll versions

Showing 50 of 382 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3438?
A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.
How severe is CVE-2021-3438?
CVE-2021-3438 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 2.90% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3438?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3438?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST