7.5
CVSSv3

CVE-2023-4694

Published: 14/12/2023 Updated: 18/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header.

Vulnerable Product Search on Vulmon Subscribe to Product

hp officejet_pro_8730_d9l19a_firmware

hp officejet_pro_8730_m9l74a_firmware

hp officejet_pro_8730_m9l75a_firmware

hp officejet_pro_8730_m9l76a_firmware

hp officejet_pro_8730_j7a28a_firmware

hp officejet_pro_8730_j7a31a_firmware

hp officejet_pro_8730_k7s34a_firmware

hp officejet_pro_8730_k7s35a_firmware

hp officejet_pro_8730_m9l80a_firmware

hp officejet_pro_8730_j7a29a_firmware

hp officejet_pro_8730_k7s36a_firmware

hp officejet_pro_8730_t0g54a_firmware

Github Repositories

POC of DOS vulnerability in HP OfficeJet and LaserJet printers

HP-PrnStatus-DOS (CVE-2023-4694) Summary This is a simple POC for a DOS vulnerability that has been found to affect HP OfficeJet and HP LaserJet printers This has been confirmed to impact multiple hardware models and multiple firmware versions for these models Method of Operation The vulnerability is triggered by sending a valid SOAP envelope that does not contain a header to