According to a security advisory from HP, some HP Enterprise LaserJet and HP LaserJet Managed printers may be susceptible to information exposure when IPsec is enabled with FutureSmart version 5.6.
All HP Enterprise devices run HP FutureSmart firmware, making it simple to administer and maintain various features across your fleet, from the user experience to app security support.
Users can operate and set up printers using a control panel located at the printer or a web browser for remote access.
The IP network security protocol suite, IPsec (Internet Protocol Security), is used in business networks to secure internal and external communications and stop unwanted access to resources, such as printers.
A critical rating and a CVSS v3.1 score of 9.1 have been given to the issue, tracked as CVE-2023-1707.
Indeed, HP has not yet released a fix for the concerned firmware. According to HP, a new firmware version that rectifies the problem should be available in 90 days.
Notably, the information disclosure flaw in this condition could give an attacker access to sensitive information sent between the affected HP printers and other networked devices.
“HP recommends immediately reverting to a prior version of the firmware (FutureSmart version 5.5.0.3). Updated firmware to address the issue is expected within 90 days”.
Users are advised to download the firmware package from HP’s official download portal, where they can choose their printer model and download the necessary software.
Network Security Checklist – Download Free E-Book
Related Read:
The text-to-dense representation techniques vary, evolving from character bi-grams to advanced subword vectorizers, combating OOV…
In the ever-evolving realm of cybersecurity, Promon, a trailblazer in mobile security solutions, has brought…
Hackers use Remote Access Trojans (RATs) to gain unauthorized access and control over a victim's…
Black Basta, the fourth-most active ransomware strain with more than 329 victims, has reportedly made…
Notepad++ has been discovered with an uncontrolled search path vulnerability, which could allow threat actors…
WhatsApp has announced the rollout of a new feature to safeguard sensitive conversations. The Secret…