HP LaserJet Pro Printers OpenSSL Heartbeat Information Disclosure (HPSBPI03014) (Heartbleed)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote printer is potentially affected by an information
disclosure vulnerability.

Description :

The version of the remote HP printer is potentially affected by an
out-of-bounds read error, known as the 'Heartbleed Bug' in the
included OpenSSL version.

This error is related to handling TLS heartbeat extensions that could
allow an attacker to obtain sensitive information such as primary key
material, secondary key material, and other protected content.

See also :

http://www.nessus.org/u?3ccffdc9

Solution :

Upgrade the firmware in accordance with the vendor's advisory.

Risk factor :

High / CVSS Base Score : 9.4
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N)
CVSS Temporal Score : 8.2
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 73806 ()

Bugtraq ID: 66690

CVE ID: CVE-2014-0160