Number: AV18-128
Date: 08 August 2018
Purpose
The purpose of this advisory is to bring attention to the recently released security updates for HP Enterprise printers.
Assessment
HP has released security patches to address a vulnerability of Remote Code Execution which could allow potential execution of arbitrary code in multiple HP Inkjet printers.
Affected Versions:
- HP PageWide 352dw: J6U57B
- HP PageWide Managed MFP P57750dw: J9V82A, J9V82B, J9V82C, J9V82D
- HP PageWide Managed MFP P77740dn: Y3Z57
- HP PageWide Managed MFP P77740dw: W1B33
- HP PageWide Managed MFP P77740z: W1B39
- HP PageWide Managed MFP P77750z: W1B37
- HP PageWide Managed MFP P77760z: W1B38
- HP PageWide Managed P55250dw: J6U55A, J6U55B, J6U55C, J6U55D
- HP PageWide Managed P75050dn: Y3Z45
- HP PageWide Managed P75050dw: Y3Z47
- HP PageWide MFP 377dw: J9V80A, J9V80B
- HP PageWide Pro 452dn: D3Q15A, D3Q15B, D3Q15D
- HP PageWide Pro 552dw: D3Q17A, D3Q17C, D3Q17D
- HP PageWide Pro 750dn: Y3Z46
- HP PageWide Pro 750dw: Y3Z44
- HP PageWide Pro MFP 477dn: D3Q19A, D3Q19D
- HP PageWide Pro MFP 477dw: D3Q20A, D3Q20B, D3Q20C, D3Q20D
- HP PageWide Pro MFP 577dw: D3Q21A, D3Q21C, D3Q21D
- HP PageWide Pro MFP 577z: K9Z76A, K9Z76D
- HP PageWide Pro MFP 772dn: W1B31
- HP PageWide Pro MFP 772dw: Y3Z54
- HP PageWide Pro 452dw: D3Q16A, D3Q16B, D3Q16C, D3Q16D
- HP DesignJet rugged case: N9M07A
- HP Designjet T120 24-in ePrinter: CQ891A
- HP Designjet T120 24-in Printer: CQ891B
- HP Designjet T120 24-in Printer (2018 edition): CQ891C
- HP Designjet T120 24-in Rmkt ePrinter: CQ891AR
- HP Designjet T520 24-in ePrinter: CQ890A
- HP Designjet T520 24-in Printer: CQ890B
- HP Designjet T520 24-in Printer (2018 edition): CQ890C
- HP Designjet T520 24-in Printer (2018 edition): CQ890D
- HP Designjet T520 24-in Printer (2018 edition, legless): CQ890E
- HP Designjet T520 24-in Rmkt ePrinter: CQ890AR
- HP Designjet T520 36-in ePrinter: CQ893A
- HP Designjet T520 36-in Printer: CQ893B
- HP Designjet T520 36-in Printer (2018 edition): CQ893C
- HP Designjet T520 36-in Printer (2018 edition, legless): CQ893E
- HP Designjet T520 36-in Rmkt ePrinter: CQ893AR
- HP DesignJet T730 36in Printer: F9A29A
- HP DesignJet T730 36in Printer: F9A29B
- HP Designjet T730 with Rugged Case: T5D66A
- HP DesignJet T830 24in eMFP Printer: F9A28A
- HP DesignJet T830 24-in MFP Printer: F9A28B
- HP DesignJet T830 MFP with Armor Case: 1JL02B
- HP DesignJet T830 MFP with Armour Case: 1JL02A
- HP DesignJet T830 MFP with Rugged Case: T5D67A
- HP Officejet, HP Deskjet and HP Envy
- HP AMP 1xx Printer series: T8X39 - T8X44: 1SH08, 3AW44A - 3AW51A
- HP Deskjet 2540 All-in-One: A9U19A - A9U28B, D3A78B - D3A82A
- HP DeskJet 2600 All-in-One Printer: 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A
- HP DeskJet 2600 All-in-One Printer: CZ992A, L9D57A, N4L17A
- HP Deskjet 2620 Ink Advantage series: D4H22A - D4H24B
- HP Deskjet 3540 series: A9T81A, A9T81C, A9T83B
- HP DeskJet 3630 series: F5S43A - F5S57A, K4T93A - K4T99B, K4U00B - K4U04B
- HP DeskJet 3700 All-in-One Printer series: J9V86A
- HP DeskJet 3700 All-in-One Printer series: J9V86A - J9V96A, T8W51A - T8W73A
- HP Deskjet 4510 series: A9J41 - A9J43
- HP DeskJet 4530 series: F0V64 - F0V66, J6U63, W3U23 - W3U24
- HP DeskJet 4720 series: F5S65A - F5S66A, L8L91A
- HP DeskJet 5000 series: M2U86 - M2U90
- HP DeskJet 5275 All-in-One Printer: M2U76 - M2U80
- HP DeskJet 5640 series: B9S57C
- HP DeskJet 5730 series: F5S60A - F5S61A, T0A23A - T0A25A
- HP DeskJet GT 5820 All-in-One Printer series: M2Q28A, P0R21A, X3B09A, 2ND31A
- HP Deskjet Ink Advantage 2540 All-in-One: A9U23 - A9U28
- HP DeskJet Ink Advantage 2600 All-in-One Printer: V1N02A - V1N02C
- HP DeskJet Ink Advantage 2600 All-in-One Printer: Y5Z00A - Y5Z07B
- HP DeskJet Ink Advantage 3630 All-in-One Printer: F5S43 - F5S57, K9U05B
- HP DeskJet Ink Advantage 3700 All-in-One Printer series: 1DT61A - 1DT62A, 3YZ74A - 3YZ75A, 4SC29A - 4SC30A, J9V87A - J9V89B, T8W35A - T8W50C
- HP Deskjet Ink Advantage 3830 e-All-in-One Printer: F5R96A - F5R98B, K7V42C - K7V43C
- HP Deskjet Ink Advantage 4615 All-in-One Printer: CZ283A - CZ283C
- HP Deskjet Ink Advantage 4625 e-All-in-One: CZ284A - CZ284C
- HP Deskjet Ink Advantage 4640 e-All-in-One Printer series: B4L08A - B4L10A
- HP DeskJet Ink Advantage 4670 All-in-One Printer: F1H97 - F1H199
- HP Deskjet Ink Advantage 5525 e-All-in-One: CZ282A - CZ282C
- HP DeskJet Ink Advantage 5570 All-in-One printer: G0V48B, G0V48C
- HP Deskjet Ink Advantage 6525 e-All-in-One: CZ276A - CZ76C
- HP Envy 120 Series: CQ176 - CQ190
- HP ENVY 4500 series: A9T80A, A9T80B, A9T89A, D3P93A
- HP ENVY 4510 All-in-One Printer: K9H48 - K9H57
- HP ENVY 4520 series: F0V63, F0V67 - F0V74, K9T01 - K9T10, J6U59 - J6U62, J6U69 - J6U70, K9H57,
- W3U25 - W3U27
- HP ENVY 5000 series: M2U85, M2U91-M2U94, Z4A54 - Z4A78
- HP ENVY 5530 series: A9J40A - A9J48B, D4J85B - D4J86B
- HP ENVY 5540 All-in-One Printer: G0V47, G0450 - G0V56, K7C84 - K7C93, K7G86 - K7G90
- HP ENVY 5640 series: B9S56A, B9S58A - B9S65A, F8B05A, F8B13A
- HP ENVY 5660 series: F8B04A, F8B06A - F8B08A, F8B12A
- HP ENVY 7640 series: E4W43-E4W48
- HP ENVY Photo 6200 All-in-One Printer series: K7G18A-K7G29A
- HP ENVY Photo 7100 All-in-One Printer series: K7G93A-K7G99
- HP ENVY Photo 7100 All-in-One Printer series: K7S00A
- HP Ink Tank 310: Z6Z11A
- HP Ink Tank Wireless 410: Z4B53A - Z4B55A, Z6Z95A, Z6Z97A
- HP Officejet Pro X451dn Printer: CN459A
- HP Officejet Pro X451dw Printer: CN463A
- HP Officejet Pro X476dn MFP: CN460A
- HP Officejet Pro X476dw MFP: CN461A
- HP Officejet Pro X551dw Printer: CV037A
- HP Officejet Pro X576dn MFP: CN462A
- HP Officejet Pro X576dw MFP: C598A
- HP OfficeJet 200 Mobile series: CZ993A, L9B95A
- HP OfficeJet 202 Mobile series: N4L14C, N4K99C
- HP OfficeJet 252 Mobile All-in-One: N4L18C
- HP Officejet 2620 series: D4H21A - D4H21B, D4H25A - D4H29B
- HP Officejet 3830 e-All-in-One Printer: F5R95, F5S00 - F5S04, K7V35 - K7V49
- HP Officejet 4610 e-All-in-One Printer: CR771A
- HP Officejet 4620 e-All-in-One Printer: CZ152A - CZ152C
- HP Officejet 4622 e-All-in-One Printer: CZ294A - CZ296B
- HP Officejet 4630 e-All-in-One Printer series: B4L03 - B4L07A, D4J74 - D4J78
- HP OfficeJet 4650 All-in-One Printer: F1H96, F1J00 - F1J07, F9D36 - F9D38, K9V76 - K9V85, V6D27- V6D32
- HP OfficeJet 5200 AlI-in-One Printer: M2U75, M2U81-M2U84, Z4B12 - Z4B36
- HP Officejet 5740 series: B9S76-B9S85, F8B09-F8B11, T1P36-T1P38
- HP Officejet 6220 / HP Officejet Pro 6230 ePrinter: E3E03A, C9S13A
- HP OfficeJet 6600 e-All-in-One: CN581A
- HP OfficeJet 6700 Premium e-All-in-One: CN583A
- HP Officejet 6810/6820 e-All-in-One Printer: F0M65A, G1W52A
- HP OfficeJet 6950 All-in-One: P4C78A - P4C87A, T3P03A, T3P04A
- HP OfficeJet Pro 6960 All-in-One: J7K33A - J7K39A, T0F28A - T0F38A, T0G25A - T0G26A
- HP Officejet 7110 Wide Format ePrinter: CR768A
- HP Officejet 7510 Wide Format All-in-One Printer: G3J47A
- HP Officejet 7610 series Wide Format e-All-in-One Printer: CR769A
- HP Officejet 7612 Wide Format e-All-in-One: G1X85A
- HP Officejet Pro 251dw Printer: CV136A
- HP Officejet Pro 276dw Multifunction Printer: CR7770A
- HP Officejet Pro 3610 Black and White Printer: CZ292A
- HP Officejet Pro 3620 Black and White Printer: CZ293A
- HP Officejet Pro 6830 e-All-in-One Printer: E3E02A, J2D37A
- HP OfficeJet Pro 6970 All-in-One Printer: J7K34A - J7K42A, T0F29A - T0F40A
- HP OfficeJet Pro 7720 Wide Format All-in-One: Y0S18A
- HP OfficeJet Pro 7730 Wide Format All-in-One: Y0S19A
- HP OfficeJet Pro 7740 Wide Format All-in-One: G5J38A, T1P99, T1Q00 - T1Q02
- HP OfficeJet Pro 8210 Printer
- HP OfficeJet Pro 8216: D9L63A, D9L64A, T0G70A, J3P68A
- HP OfficeJet Pro 8600A e-All-in-One: CM749A
- HP OfficeJet Pro 8600A Plus e-All-in-One: CM750A
- HP OfficeJet Pro 8600A Premium e-All-in-One: CN577A
- HP Officejet Pro 8610 e-All-in-One Printer: A7F64A, D7Z36A, E1D34A, J5T77A, T0K98A
- HP Officejet Pro 8620 e-All-in-One Printer: A7F65A, D7Z37A
- HP Officejet Pro 8630 e-All-in-One Printer: A7F66A
- HP Officejet Pro 8640 e-All-in-One Printer: E2D42A
- HP Officejet Pro 8660 e-All-in-One Printer: E1D36A
- HP OfficeJet Pro 8710 All-in-One Printer: D9L18A, J6X76A - J6X78A, J6X80A - J6X81A, K7S37A - K7S38A, M9L65A - M9L66A, M9L70A, M9L81A, T0G45A - T0G49A
- HP OfficeJet Pro 8720 All-in-One Printer : D9L19A, J7A28A, J7A31A, K7S34A - K7S36A, M9L73A - M9L75A, M9L80A, T0G50A - T0G51A,T0G54A,
- T6T77A
- HP OfficeJet Pro 8730: D9L20A
- HP OfficeJet Pro 8732M All-in-One Printer: T0G56A - T0G59A
- HP OfficeJet Pro 8740: K7S42A
- HP Photosmart 5510 series: CQ176-CQ190
- HP Photosmart 5510d series: CQ761-CQ769
- HP Photosmart 5520 series e-All-in-One
- HP Photosmart 5521 e-All-in-One
- HP Photosmart 5522 e-All-in-One
- HP Photosmart 5524 e-All-in-One
- HP Photosmart 5525 e-All-in-One: CX042 - CX049
- HP Photosmart 6510 series: CQ761-CQ769
- HP Photosmart 6520 e-All-in-One: CX017A - CX021C
- HP Photosmart 7520 series: CZ025A, CZ045A - CZ046A
- HP Photosmart Plus All-in-One B210 series: B210
- HP Smart Tank Wireless 450: Z4B07A, Z4B56A
CVE Reference: CVE-2018-5924, CVE-2018-5925
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications or workarounds to affected platforms accordingly.
References: