ID

VAR-201801-1001


CVE

CVE-2017-2747


TITLE

plural HP DesignJet and Latex Vulnerabilities related to certificate and password management in products

Trust: 0.8

sources: JVNDB: JVNDB-2017-012277

DESCRIPTION

HP has identified a potential security vulnerability before IG_11_00_00.10 for DesignJet T790, T795, T1300, T2300, before MRY_04_05_00.5 for DesignJet T920, T930, T1500, T1530, T2500, T2530, before AENEAS_03_04_00.9 for DesignJet T3500, before NEXUS_01_12_00.11 for Latex 310, 330, 360, 370, before NEXUS_03_12_00.15 for Latex 315, 335, 365, 375, before STORM_00_05_01.6 for Latex 560, 570 and Latex 110 that may expose the credentials of the SMTP server configured to receive and process emails generated by the printers. plural HP DesignJet and Latex The product contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HPDesignJetT790 and other printers are the United States HP (HP) company. There are SMTP credential vulnerabilities in several HP products. An attacker could exploit the vulnerability to obtain a certificate for the SMTP server. HP DesignJet T790, etc. The following products and versions are affected: HP DesignJet T790 prior to IG_11_00_00.10; DesignJet T795 prior to IG_11_00_00.10; DesignJet T1300 prior to IG_11_00_00.10; DesignJet T2300 prior to IG_11_00_00.10; DesignJet T920 prior to MRY_04_05 DesignJet T930 prior to MRY_04_05_00.5; DesignJet T1500 prior to MRY_04_05_00.5; DesignJet T1530 prior to MRY_04_05_00.5; DesignJet T2500 prior to MRY_04_05_00.5; Latex 310 before NEXUS_01_12_00.11; Latex 330 before NEXUS_01_12_00.11; Latex 360 before NEXUS_01_12_00.11; Latex 370 before NEXUS_01_12_00.11 before 305_Latex Versions; Latex 335 prior to NEXUS_03_12_00.15; Latex 365 prior to NEXUS_03_12_00.15; Latex 375 prior to NEXUS_03_12_00.15; Latex 560 prior to STORM_00_05_01.6; Latex 570 prior to STORM_00_05_01.6

Trust: 2.34

sources: NVD: CVE-2017-2747 // JVNDB: JVNDB-2017-012277 // CNVD: CNVD-2018-04191 // VULHUB: VHN-110950 // VULMON: CVE-2017-2747

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-04191

AFFECTED PRODUCTS

vendor:hpmodel:110scope:lteversion:nexus_00_04_53.8

Trust: 1.0

vendor:hpmodel:t2300scope:lteversion:ig_11_00_00.09

Trust: 1.0

vendor:hpmodel:570scope:lteversion:storm_00_05_01.5

Trust: 1.0

vendor:hpmodel:560scope:lteversion:storm_00_05_01.5

Trust: 1.0

vendor:hpmodel:t1530scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hpmodel:t790scope:lteversion:ig_11_00_00.09

Trust: 1.0

vendor:hpmodel:370scope:lteversion:nexus_01_12_00.10

Trust: 1.0

vendor:hpmodel:315scope:lteversion:nexus_03_12_00.14

Trust: 1.0

vendor:hpmodel:330scope:lteversion:nexus_01_12_00.10

Trust: 1.0

vendor:hpmodel:t2500scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hpmodel:t2530scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hpmodel:t795scope:lteversion:ig_11_00_00.09

Trust: 1.0

vendor:hpmodel:t1500scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hpmodel:t920scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hpmodel:375scope:lteversion:nexus_03_12_00.14

Trust: 1.0

vendor:hpmodel:310scope:lteversion:nexus_01_12_00.10

Trust: 1.0

vendor:hpmodel:335scope:lteversion:nexus_03_12_00.14

Trust: 1.0

vendor:hpmodel:360scope:lteversion:nexus_01_12_00.10

Trust: 1.0

vendor:hpmodel:365scope:lteversion:nexus_03_12_00.14

Trust: 1.0

vendor:hpmodel:t1300scope:lteversion:ig_11_00_00.09

Trust: 1.0

vendor:hpmodel:t3500scope:lteversion:aeneas_03_04_00.8

Trust: 1.0

vendor:hpmodel:t930scope:lteversion:mry_04_05_00.4

Trust: 1.0

vendor:hewlett packardmodel:designjet t1300scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:designjet t2300scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:designjet t790scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:designjet t795scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:designjet t920scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:latex 110scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:latex 310scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:latex 330scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:latex 360scope: - version: -

Trust: 0.8

vendor:hewlett packardmodel:latex 370scope: - version: -

Trust: 0.8

vendor:hpmodel:latex <nexus 01 12 00.11scope:eqversion:310

Trust: 0.6

vendor:hpmodel:latex <nexus 01 12 00.11scope:eqversion:330

Trust: 0.6

vendor:hpmodel:latex <nexus 01 12 00.11scope:eqversion:360

Trust: 0.6

vendor:hpmodel:latex <nexus 01 12 00.11scope:eqversion:370

Trust: 0.6

vendor:hpmodel:latex <nexus 03 12 00.15scope:eqversion:315

Trust: 0.6

vendor:hpmodel:latex <nexus 03 12 00.15scope:eqversion:335

Trust: 0.6

vendor:hpmodel:latex <nexus 03 12 00.15scope:eqversion:365

Trust: 0.6

vendor:hpmodel:latex <nexus 03 12 00.15scope:eqversion:375

Trust: 0.6

vendor:hpmodel:latex <storm 00 05 01.6scope:eqversion:570

Trust: 0.6

vendor:hpmodel:latex <storm 00 05 01.6scope:eqversion:560

Trust: 0.6

vendor:hpmodel:latexscope:eqversion:110

Trust: 0.6

vendor:hpmodel:designjet t3500 <aeneas 03 04 00.9scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t790 <ig 11 00 00.10scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t795 <ig 11 00 00.10scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t1300 <ig 11 00 00.10scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t2300 <ig 11 00 00.10scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t920 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t930 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t1500 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t1530 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t2500 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:designjet t2530 <mry 04 05 00.5scope: - version: -

Trust: 0.6

vendor:hpmodel:t2530scope:eqversion:mry_04_05_00.4

Trust: 0.6

vendor:hpmodel:t1530scope:eqversion:mry_04_05_00.4

Trust: 0.6

vendor:hpmodel:t1300scope:eqversion:ig_11_00_00.09

Trust: 0.6

vendor:hpmodel:t2300scope:eqversion:ig_11_00_00.09

Trust: 0.6

vendor:hpmodel:t790scope:eqversion:ig_11_00_00.09

Trust: 0.6

vendor:hpmodel:t2500scope:eqversion:mry_04_05_00.4

Trust: 0.6

vendor:hpmodel:t920scope:eqversion:mry_04_05_00.4

Trust: 0.6

vendor:hpmodel:t1500scope:eqversion:mry_04_05_00.4

Trust: 0.6

vendor:hpmodel:t795scope:eqversion:ig_11_00_00.09

Trust: 0.6

vendor:hpmodel:t930scope:eqversion:mry_04_05_00.4

Trust: 0.6

sources: CNVD: CNVD-2018-04191 // JVNDB: JVNDB-2017-012277 // CNNVD: CNNVD-201801-873 // NVD: CVE-2017-2747

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-2747
value: HIGH

Trust: 1.0

NVD: CVE-2017-2747
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-04191
value: LOW

Trust: 0.6

CNNVD: CNNVD-201801-873
value: HIGH

Trust: 0.6

VULHUB: VHN-110950
value: LOW

Trust: 0.1

VULMON: CVE-2017-2747
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2017-2747
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-04191
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-110950
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-2747
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-04191 // VULHUB: VHN-110950 // VULMON: CVE-2017-2747 // JVNDB: JVNDB-2017-012277 // CNNVD: CNNVD-201801-873 // NVD: CVE-2017-2747

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-255

Trust: 0.9

sources: VULHUB: VHN-110950 // JVNDB: JVNDB-2017-012277 // NVD: CVE-2017-2747

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201801-873

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201801-873

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012277

PATCH

title:HPSBPI03563url:https://support.hp.com/us-en/document/c05624457

Trust: 0.8

title:Patch for multiple HP product SMTP certificate vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/120059

Trust: 0.6

title:Multiple HP Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78025

Trust: 0.6

title:HP: SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBPI03563 rev 1 - SMTP Credentials Vulnerability for HP Designjet and HP Latex printersurl:https://vulmon.com/vendoradvisory?qidtp=hp_bulletin&qid=c59b43ed838b4d3cc6b6a853985fa234

Trust: 0.1

title:HP: HPSBPI03563 rev 1 - SMTP Credentials Vulnerability for HP Designjet and HP Latex printersurl:https://vulmon.com/vendoradvisory?qidtp=hp_bulletin&qid=HPSBPI03563

Trust: 0.1

title:HP: SUPPORT COMMUNICATION- SECURITY BULLETIN HPSBPI03563 rev 1 - SMTP Credentials Vulnerability for HP Designjet and HP Latex printersurl:https://vulmon.com/vendoradvisory?qidtp=hp_bulletin&qid=b3752f68dbc7c4bc587f927d56c9be97

Trust: 0.1

sources: CNVD: CNVD-2018-04191 // VULMON: CVE-2017-2747 // JVNDB: JVNDB-2017-012277 // CNNVD: CNNVD-201801-873

EXTERNAL IDS

db:NVDid:CVE-2017-2747

Trust: 3.2

db:JVNDBid:JVNDB-2017-012277

Trust: 0.8

db:CNNVDid:CNNVD-201801-873

Trust: 0.7

db:CNVDid:CNVD-2018-04191

Trust: 0.6

db:VULHUBid:VHN-110950

Trust: 0.1

db:VULMONid:CVE-2017-2747

Trust: 0.1

sources: CNVD: CNVD-2018-04191 // VULHUB: VHN-110950 // VULMON: CVE-2017-2747 // JVNDB: JVNDB-2017-012277 // CNNVD: CNNVD-201801-873 // NVD: CVE-2017-2747

REFERENCES

url:https://support.hp.com/us-en/document/c05624457

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-2747

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-2747

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2018-04191 // VULHUB: VHN-110950 // VULMON: CVE-2017-2747 // JVNDB: JVNDB-2017-012277 // CNNVD: CNNVD-201801-873 // NVD: CVE-2017-2747

SOURCES

db:CNVDid:CNVD-2018-04191
db:VULHUBid:VHN-110950
db:VULMONid:CVE-2017-2747
db:JVNDBid:JVNDB-2017-012277
db:CNNVDid:CNNVD-201801-873
db:NVDid:CVE-2017-2747

LAST UPDATE DATE

2024-11-23T22:12:41.915000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-04191date:2018-03-02T00:00:00
db:VULHUBid:VHN-110950date:2019-10-03T00:00:00
db:VULMONid:CVE-2017-2747date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-012277date:2018-03-05T00:00:00
db:CNNVDid:CNNVD-201801-873date:2019-10-23T00:00:00
db:NVDid:CVE-2017-2747date:2024-11-21T03:24:06.410

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-04191date:2018-03-02T00:00:00
db:VULHUBid:VHN-110950date:2018-01-23T00:00:00
db:VULMONid:CVE-2017-2747date:2018-01-23T00:00:00
db:JVNDBid:JVNDB-2017-012277date:2018-03-05T00:00:00
db:CNNVDid:CNNVD-201801-873date:2018-01-24T00:00:00
db:NVDid:CVE-2017-2747date:2018-01-23T16:29:01.570