HIGH · 10.0

CVE-2014-7889

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSLineDisplay.ocx for Retail RP7 VFD Custo...

Vulnerability Description

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSLineDisplay.ocx for Retail RP7 VFD Customer Display monitors, Retail Integrated 2x20 Display monitors, Retail Integrated 2x20 Complex monitors, POS Pole Display monitors, Graphical POS Pole Display monitors, and LCD Pole Display monitors, aka ZDI-CAN-2511.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HpOle Point Of Sale Driver<= 1.13.001
HpGraphical Pos Pole Display Qz704AaAll versions
HpLcd Pole Display F7A93AaAll versions
HpPos Pole Display Fk225AaAll versions
HpRetail Integrated 2X20 Complex G7G29AaAll versions
HpRetail Integrated 2X20 Display G6U79AaAll versions
HpRetail Rp7 Vfd Customer Display Qz701AaAll versions

References

FAQ

What is CVE-2014-7889?

CVE-2014-7889 is a vulnerability with a CVSS score of 10.0 (HIGH). The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSLineDisplay.ocx for Retail RP7 VFD Custo...

How severe is CVE-2014-7889?

CVE-2014-7889 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7889?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Ole Point Of Sale Driver, Hp Graphical Pos Pole Display Qz704Aa, Hp Lcd Pole Display F7A93Aa, Hp Pos Pole Display Fk225Aa, Hp Retail Integrated 2X20 Complex G7G29Aa.