Back
CVE-2018-5924
CRITICAL
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.
Published: Aug 13, 2018
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (270)
| Vendor | Product | Version |
|---|---|---|
| hp | t8x44_firmware | 1828a |
| hp | 3aw51a_firmware | 1828a |
| hp | a9u28b_firmware | 1828b |
| hp | d3a82a_firmware | 1828b |
| hp | v1n08a_firmware | 1828a |
| hp | y5h80a_firmware | 1828a |
| hp | d4h24b_firmware | 1826a |
| hp | f5s57a_firmware | 1829a |
| hp | k4t99b_firmware | 1829a |
| hp | k4u04b_firmware | 1829a |
| hp | t8x39_firmware | 1828a |
| hp | 1sh08_firmware | 1828a |
| hp | 3aw44a_firmware | 1828a |
| hp | a9u19a_firmware | 1828b |
| hp | d3a78b_firmware | 1828b |
| hp | 4uj28b_firmware | 1828a |
| hp | v1n01a_firmware | 1828a |
| hp | y5h60a_firmware | 1828a |
| hp | d4h22a_firmware | 1826a |
| hp | j6u57b_firmware | 001.1829a |
…and 250 more
GitHub Security Advisory GHSA-4xrc-rh76-cwgr
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously...
References (8)
- http://www.securityfocus.com/bid/105010 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041415 Third Party Advisory, VDB Entry
- https://research.checkpoint.com/sending-fax-back-to-the-dark-ages/ Third Party Advisory
- https://support.hp.com/us-en/document/c06097712 Vendor Advisory
- http://www.securityfocus.com/bid/105010 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041415 Third Party Advisory, VDB Entry
- https://research.checkpoint.com/sending-fax-back-to-the-dark-ages/ Third Party Advisory
- https://support.hp.com/us-en/document/c06097712 Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
12.23%
Top 4% most likely to be exploited
Threat Score
42.9 / 100
Data Sources
NVD
EPSS
GitHub