Vulnerabilities > CVE-2017-2741 - Unspecified vulnerability in HP products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.
Vulnerable Configurations
Exploit-Db
description HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit). CVE-2017-2741. Remote exploit for Unix platform. Tags: Metasploit Framework (MSF), Remote file exploits/unix/remote/45273.rb id EDB-ID:45273 last seen 2018-10-07 modified 2018-08-27 platform unix port published 2018-08-27 reporter Exploit-DB source https://www.exploit-db.com/download/45273/ title HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit) type remote description HP PageWide Printers / HP OfficeJet Pro Printers (OfficeJet Pro 8210) - Arbitrary Code Execution. CVE-2017-2741. Remote exploit for Hardware platform file exploits/hardware/remote/42176.py id EDB-ID:42176 last seen 2017-06-15 modified 2017-06-14 platform hardware port 9100 published 2017-06-14 reporter Exploit-DB source https://www.exploit-db.com/download/42176/ title HP PageWide Printers / HP OfficeJet Pro Printers (OfficeJet Pro 8210) - Arbitrary Code Execution type remote
Metasploit
description | The module exploits a path traversal via Jetdirect to gain arbitrary code execution by writing a shell script that is loaded on startup to /etc/profile.d. Then, the printer is restarted using SNMP. Impacted printers: HP PageWide Managed MFP P57750dw HP PageWide Managed P55250dw HP PageWide Pro MFP 577z HP PageWide Pro 552dw HP PageWide Pro MFP 577dw HP PageWide Pro MFP 477dw HP PageWide Pro 452dw HP PageWide Pro MFP 477dn HP PageWide Pro 452dn HP PageWide MFP 377dw HP PageWide 352dw HP OfficeJet Pro 8730 All-in-One Printer HP OfficeJet Pro 8740 All-in-One Printer HP OfficeJet Pro 8210 Printer HP OfficeJet Pro 8216 Printer HP OfficeJet Pro 8218 Printer Please read the module documentation regarding the possibility for leaving an unauthenticated telnetd service running as a side effect of this exploit. |
id | MSF:EXPLOIT/LINUX/MISC/HP_JETDIRECT_PATH_TRAVERSAL |
last seen | 2020-06-02 |
modified | 2018-08-23 |
published | 2017-12-29 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/linux/misc/hp_jetdirect_path_traversal.rb |
title | HP Jetdirect Path Traversal Arbitrary Code Execution |
Nessus
NASL family | General |
NASL id | HP_PRINTER_RCE.NASL |
description | The remote HP OfficeJet Pro or PageWide Pro printer is affected by an unspecified flaw in the Printer Job Language (PJL) interface, within various PJL and PostScript file handling functions, due to improper sanitization of user-supplied input. An unauthenticated, remote attacker can exploit this, via directory traversal, to write arbitrary files, resulting in the execution of arbitrary code. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 100461 |
published | 2017-05-26 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/100461 |
title | HP OfficeJet Pro and PageWide Pro PJL Interface Directory Traversal RCE |
code |
|
Packetstorm
data source https://packetstormsecurity.com/files/download/142940/hppagewide-exec.txt id PACKETSTORM:142940 last seen 2017-06-15 published 2017-06-14 reporter Jacob Baines source https://packetstormsecurity.com/files/142940/HP-PageWide-OfficeJet-Pro-Printers-Arbitrary-Code-Execution.html title HP PageWide / OfficeJet Pro Printers Arbitrary Code Execution data source https://packetstormsecurity.com/files/download/149105/hp_jetdirect_path_traversal.rb.txt id PACKETSTORM:149105 last seen 2018-08-28 published 2018-08-27 reporter Jacob Baines source https://packetstormsecurity.com/files/149105/HP-Jetdirect-Path-Traversal-Arbitrary-Code-Execution.html title HP Jetdirect Path Traversal Arbitrary Code Execution