Vulnerability Description
Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Designjet Z6 Firmware | < jgr6_09_22_51.2 |
| Hp | Designjet Z6 | - |
| Hp | Designjet Z6Dr Firmware | < jgr6_09_22_51.2 |
| Hp | Designjet Z6Dr | - |
| Hp | Designjet Z9 Firmware | < jgr9_09_22_51.2 |
| Hp | Designjet Z9 | - |
| Hp | Designjet Z9Dr Firmware | < jgr9_09_22_51.2 |
| Hp | Designjet Z9Dr | - |
| Hp | Designjet Z9\+ Pro Firmware | - |
| Hp | Designjet Z9\+ Pro | - |
| Hp | Pagewide Xl 4700 | _firmware |
| Hp | Pagewide Xl 4500 | _firmware |
| Hp | Pagewide Xl 4100 | _firmware |
| Hp | Pagewide Xl 4600 | _firmware |
| Hp | Pagewide Xl 8000 | _firmware |
References
- https://support.hp.com/us-en/document/ish_7869666-7869691-16/hpsbpi03837Vendor Advisory
- https://support.hp.com/us-en/document/ish_7869666-7869691-16/hpsbpi03837Vendor Advisory
FAQ
What is CVE-2023-1526?
CVE-2023-1526 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Certain DesignJet and PageWide XL TAA compliant models may have risk of potential information disclosure if the hard disk drive is physically removed from the printer.
How severe is CVE-2023-1526?
CVE-2023-1526 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1526?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Designjet Z6 Firmware, Hp Designjet Z6, Hp Designjet Z6Dr Firmware, Hp Designjet Z6Dr, Hp Designjet Z9 Firmware.