The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hplip | Mar 31, 2017 | Jul 30, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 29, 2015 |
| Suse | — | Upgrade hplip-hpijsUpgrade hplip-develUpgrade hplip-saneUpgrade hplip | Dec 9, 2016 | Jul 30, 2015 |
| Ubuntu | — | Upgrade hplip-data | Nov 8, 2024 | Aug 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub