HP MFP Digital Sending Software < 4.18.3 Local Unspecified Authentication Bypass

Medium Nessus Plugin ID 46676


The remote Windows host contains an application that is affected by an authentication bypass vulnerability.


The remote Windows host contains a version of HP MFP Digital Sending Software earlier than 4.18.3. Such versions are potentially affected by an unspecified authentication bypass vulnerability.

A local attacker, exploiting this flaw, reportedly can gain unauthorized access to 'Send to email' and other functionalities of an HP Multifunction Peripheral (MFP) that is controlled by the HP Digital Sending Software.


Upgrade to HP MFP Digital Sending Software 4.18.5 or later.

Note that HP initially recommended upgrading to version 4.18.3. While that version does address the vulnerability, it also introduces a non-security defect and HP now recommends upgrading to version 4.18.5.

See Also



Plugin Details

Severity: Medium

ID: 46676

File Name: hp_mfp_dss_4_18_3.nasl

Version: $Revision: 1.8 $

Type: local

Agent: windows

Family: Windows

Published: 2010/05/19

Modified: 2013/06/21

Dependencies: 46675

Risk Information

Risk Factor: Medium


Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:N/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:hp:multifunction_peripheral_digital_sending_software

Required KB Items: SMB/HP_MFP_DSS/Version

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2010/05/12

Vulnerability Publication Date: 2010/05/12

Reference Information

CVE: CVE-2010-1558

BID: 40147

OSVDB: 64661