US English (US)
AU English (AUS)
Log a Support Call RBC Website
English (AUS)
US English (US)
AU English (AUS)
  • Home
  • Security

Certain HP Print Products - Potential Buffer Overflow, Remote Code Execution (CVE-2022-28721 & CVE-2022-28722)

Contact Us


Can't find what you're looking for?

Log a Support Call
  • HP
    HP Print HP Copy HP Scan HP Fax HP Apps HP Meters HP Other
  • Lexmark
    Lexmark Print Lexmark Copy Lexmark Scans Lexmark Fax Lexmark Meters Lexmark Other
  • Ricoh
    Ricoh Print Ricoh Copy Ricoh Scan Ricoh Fax Ricoh Meters Ricoh Other
  • DaaS
  • docs2me
  • ip2me
  • COVID-19
  • Recycling and Sustainability
  • Printer Monitoring
  • eMeters
  • Security
+ More

Certain HP Print Products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.

Severity

Critical

HP Reference

HPSBPI03810 rev. 1

Release date

September 21, 2022

Last updated

September 21, 2022

Category

Print

Potential Security Impact

Potential Buffer Overflow, Remote Code Execution

 

Relevant Common Vulnerabilities and Exposures (CVE) List

LIST OF CVE IDS

CVE ID

CVSS

Severity

Vector

CVE-2022-28721

9.8

Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-28722

7.1

High

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

PSR-2022-0021

Resolution

Update your printer firmware.

HP has provided firmware updates for potentially affected products listed in the table below. To obtain the updated firmware listed below, go to the HP Software and Driver Downloads, and then search for your printer model.

Affected products

Find the products affected and the firmware version that resolves the vulnerabilities.

HP inkjet printers

Review the table for affected HP inkjet printers, and the updated firmware version.

AFFECTED PRODUCTS

Product Name

Product Number

CVE-2022-28721 (CVSS 9.8)

CVE-2022-28722 (CVSS 7.3)

Updated Firmware Version

HP DeskJet Ink Advantage 5000 All-in-One Printer series

M2U86A, M2U86B, M2U86C, M2U87A, M2U87B, M2U88B, M2U89B

Affected

Not Affected

2211A or higher

HP DeskJet Ink Advantage 5200 All-in-One Printer series

M2U76A, M2U77A

Affected

Not Affected

2211C or higher

HP DeskJet Plus Ink Advantage 6000 All-in-One Printer series

5SE522A

Affected

Not Affected

001.2214A or higher

HP DeskJet Plus Ink Advantage 6400 All-in-One Printer series

5SD78A, 5SD79A

Affected

Not Affected

001.2214A or higher

HP ENVY 5000 All-in-One Printer series

M2U85B, Z4A59A, Z4A71A, M2U91B, Z4A69A, M2U92B, Z4A70A, M2U94B, Z4A73A, Z4A74A, M2U91A, M2U92A, M2U85A, M2U94A, Z4A54A, Z4A60A, Z4A61A, Z4A61B

Affected

Not Affected

2211C or higher

HP ENVY 6000 All-in-One Printer series

5SE17A, 6WD35A, 7CZ37A, 5SE18A, 5SE16A, 5SE19A, 5SE20A, 8QQ97A, 8QQ98A, 8QQ99A

Affected

Not Affected

001.2214B or higher

HP ENVY 6000e All-In-One Printer series

223N6A, 2K4V8A, 2K4W1A, 2K4W2A, 223N2A, 223N1A, 223N5A, 223N9A

Affected

Not Affected

001.2216A or higher

HP ENVY 6400e All-In-One Printer series

223R6A, 2K5L5A, 223R2A, 223R1A, 223R3A, 223R9A

Affected

Not Affected

001.2216A or higher

HP ENVY Photo 6200 All-in-One Printer series

K7G22A, K7G18A, K7G23A, Y0K15A, K7D05A

Affected

Not Affected

003.2220B or higher

HP ENVY Photo 7100 All-in-One Printer series

Z3M37A, K7G93A, Z3M52A, 3XD89A, K7G95A, K7G96A, K7G99A

Affected

Not Affected

003.2220B or higher

HP ENVY Photo 7800 All-in-One Printer series

K7R96A, K7S00A, K7S08A, K7S01A

Affected

Not Affected

003.2220B or higher

HP ENVY Pro 6400 All-in-One Printer series

5SE46A, 6WD14A, 6WD16A, 5SE47A, 5SE45A, 5SE48A, 7XK12A, 5SE50A, 8QQ86A, 8QQ87A, 8QQ88A

Affected

Not Affected

001.2214B or higher

HP OfficeJet 5200 All-in-One Printer series

M2U81A, Z4B29A, M2U81B, Z4B27A, M2U82B, Z4B28A, M2U84B, M2U82A, M2U75A, M2U84A, Z4B12A, Z4B13A, Z4B14A, Z4B18A

Affected

Not Affected

2211A or higher

HP OfficeJet 6950 All-in-One Printer series

P4C78A, P4C85A, T3P03A, P4C86A, P4C81A, P4C82A, P4C84A

Affected

Affected

001.2224A or higher

HP OfficeJet 6960 All-in-One Printer series

T0G25A, T0G26A

Affected

Affected

001.2225A or higher

HP OfficeJet 8010 All-in-One Printer series

1KR69A, 1KR58A

Affected

Not Affected

001.2213A or higher

HP OfficeJet 8010e All-in-One Printer series

228F5A

Affected

Not Affected

004.2222A or higher

HP OfficeJet 8022 All-in-One Printer

3UC65A

Affected

Not Affected

001.2213A or higher

HP OfficeJet 8022e All-in-One Printer

1K7K6A

Affected

Not Affected

004.2222A or higher

HP OfficeJet Pro 6960 All-in-One Printer series

J7K33A, T0F30A, T0F32A, T0F38A, T0F31A, J7K37A, J7K38A, J7K35A, J7K39A, T0F28A, T0F36A

Affected

Affected

001.2225A or higher

HP OfficeJet Pro 6970 All-in-One Printer series

J7K34A, T0F33A, T0F39A, T0F34A, T0F35A, J7K40A, J7K36A, J7K42A, J7K41A, T0F29A, T0F37A, T0F40A

Affected

Affected

001.2225A or higher

HP OfficeJet Pro 7720 Wide Format All-in-One Printer series

G5J56A, Y0S18A

Affected

Affected

003.2226A or higher

HP OfficeJet Pro 7730 Wide Format All-in-One Printer

L3T99A, Y0S19A

Affected

Affected

003.2226A or higher

HP OfficeJet Pro 7740 Wide Format All-in-One Printer series

G5J38A, T1P99A

Affected

Affected

002.2226A or higher

HP OfficeJet Pro 8020 All-in-One Printer series

1KR62A, 5LJ17A, 5LJ18A, 5LJ19A, 1KR57A, 1KR61A

Affected

Not Affected

001.2213A or higher

HP OfficeJet Pro 8020e All-in-One Printer series

1K7K7A

Affected

Not Affected

004.2222A or higher

HP OfficeJet Pro 8030 All-in-One Printer series

1KR62A, 5LJ17A, 5LJ18A, 5LJ19A, 1KR57A, 1KR61A, 3UC64A

Affected

Not Affected

001.2213A or higher

HP OfficeJet Pro 8030e All-in-One Printer series

5LJ14A, 5LJ15A, 5LJ16A, 3UC66A, 4KJ65A, 5LJ23A

Affected

Not Affected

004.2222A or higher

HP OfficeJet Pro 8035e All-in-One Printer

1L0H6A, 1L0H7A, 1L0H8A

Affected

Not Affected

004.2222A or higher

HP OfficeJet Pro 8210 Printer series

D9L63A, D9L64A, J3P65A, J3P66A, J3P67A, J3P68A, T0G70A

Affected

Affected

001.2225B or higher

HP OfficeJet Pro 8710 All-in-One Printer series

D9L18A, M9L66A, M9L67A, T0G46A, J6X76A, J6X78A, J6X80A, K7S37A, M9L70A, J6X77A, J6X81A, J6X79A, K7S38A, T0G47A, T0G48A, T0G49A, M9L65A

Not Affected

Affected

001.2224B or higher

HP OfficeJet Pro 8730 All-in-One Printer

D9L20A, K7S32A

Affected

Affected

001.2225B or higher

HP OfficeJet Pro 8740 All-in-One Printer series

D9L21A, K7S42A, T0G65A, K7S39A, J6X83A, K7S43A, K7S40A, K7S41A

Affected

Affected

001.2225B or higher

HP OfficeJet Pro 9010 All-in-One Printer series

1KR46A, 3UK83A, 1KR49A, 1KR42A, 1KR45A, 3UK84A, 1KR48A, 1KR54A, 1KR55A

Affected

Not Affected

002.2211C or higher

HP OfficeJet Pro 9010e All-in-One Printer series

257G3A

Affected

Not Affected

005.2210A or higher

HP OfficeJet Pro 9020 All-in-One Printer series

1MR78A, 1MR66A, 1MR67A, 1MR69A, 1MR70A, 1MR71A, 1MR72A, 1MR73A, 1MR74A, 1MR75A, 1MR76A, 1MR77A, 1MR68A, 1MR79A

Affected

Not Affected

002.2211C or higher

HP OfficeJet Pro 9020e All-in-One Printer series

226Y9A, 1G5M0A

Affected

Not Affected

005.2210A or higher

HP Smart Tank 510 Wireless All-in-One series / HP Smart Tank Plus 550 Wireless All-in-One series

4SB23A, 3YW71A, 3YW74A, 1TJ09A, 3YW70A, 1TJ10A, 1TJ11A, 3YW73A, 6HF11A, 1TJ12A, 3YW72A, 3YW75A

Affected

Not Affected

001.2219A or higher

HP Smart Tank 610 Wireless All-in-One series / HP Smart Tank Plus 650 Wireless All-in-One series

Y0F71A, Y0F72A, Y0F73A, 7XV38A, Y0F74A, 3YW48A, 3YW51A

Affected

Not Affected

001.2219A or higher

HP Tango / HP Tango X

3DP64A, 3DP65A, 3DP66A, 3YF56A, 3YF57A, 3YF58A, 3YF60A, 3YF61A, 2RY54A, 2RY55A, 2RY56A, 3YF65A, 3YF66A, 3YF67A, 3YF68A, 3YF69A, 3YF70A, 3YF59A

Affected

Not Affected

2209A or higher

HP LaserJet Pro printers

Review the table for affected HP LaserJet Pro printers, and the updated firmware version.

AFFECTED PRODUCTS

Product Name

Product Number

CVE-2022-28721 (CVSS 9.8)

CVE-2022-28722 (CVSS 7.3)

Updated Firmware Version

HP Color LaserJet MFP M478-M479 series

W1A75A, W1A76A, W1A77A, W1A81A, W1A82A, W1A79A, W1A80A, W1A78A

Affected

Not Affected

002_2208A or higher

HP Color LaserJet Pro M453-M454 series

W1Y40A, W1Y41A, W1Y46A, W1Y47A, W1Y44A, W1Y45A, W1Y43A

Affected

Not Affected

002_2208A or higher

HP LaserJet Pro M304-M305 Printer series

W1A66A, W1A46A, W1A47A, W1A48A

Affected

Not Affected

002_2208A or higher

HP LaserJet Pro M404-M405 Printer series

W1A51A, W1A53A, W1A56A, W1A63A, W1A52A, 93M22A, W1A58A, W1A59A, W1A60A, W1A57A

Affected

Not Affected

002_2208A or higher

HP LaserJet Pro MFP M428-M429 f series

W1A29A, W1A32A, W1A30A, W1A38A, W1A34A, W1A35A

Affected

Not Affected

002_2208A or higher

HP LaserJet Pro MFP M428-M429 series

W1A28A, W1A31A, W1A33A

Affected

Not Affected

002_2208A or higher

HP PageWide Pro printers

Review the table for affected HP PageWide Pro printers, and the updated firmware version.

AFFECTED PRODUCTS

Product Name

Product Number

CVE-2022-28721 (CVSS 9.8)

CVE-2022-28722 (CVSS 7.3)

Updated Firmware Version

HP PageWide 352dw Printer

J6U57A

Affected

Affected

2228B or higher

HP PageWide 377dw Multifunction Printer

J9V80A

Affected

Affected

2228B or higher

HP PageWide Managed P55250dw Printer series

J6U55A, J6U51B, J6U55B

Affected

Affected

2228B or higher

HP PageWide Managed P57750dw Multifunction Printer

J9V82A

Affected

Affected

2228B or higher

HP PageWide Managed P75050dn/dw

W1B28A, Y3Z45A W1B29A, Y3Z47A

Affected

Affected

006.2225A or higher

HP PageWide Managed P77740dn Multifunction Printer

Y3Z57A

Affected

Affected

006.2225A or higher

HP PageWide Managed P77740dw Multifunction Printer

W1B33A

Affected

Affected

006.2225A or higher

HP PageWide Managed P77740z Multifunction Printer

W1B39A

Affected

Affected

006.2225A or higher

HP PageWide Managed P77750z Multifunction Printer

W1B37A

Affected

Affected

006.2225A or higher

HP PageWide Managed P77760z Multifunction Printer

W1B38A

Affected

Affected

006.2225A or higher

HP PageWide Pro 452dn Printer series

D3Q15A

Affected

Affected

2228B or higher

HP PageWide Pro 452dw Printer series

D3Q16A

Affected

Affected

2228B or higher

HP PageWide Pro 477dn Multifunction Printer series

D3Q19A

Affected

Affected

2228B or higher

HP PageWide Pro 477dw Multifunction Printer series

D3Q20A

Affected

Affected

2228B or higher

HP PageWide Pro 552dw Printer series

D3Q17A

Affected

Affected

2228B or higher

HP PageWide Pro 577 Multifunction Printer series

D3Q21A, K9Z76A

Affected

Affected

2228B or higher

HP PageWide Pro 750dn Printer

Y3Z44A

Affected

Affected

006.2225A or higher

HP PageWide Pro 750dw Printer

A7W93A, Y3Z46A

Affected

Affected

006.2225A or higher

HP PageWide Pro 772dn Multifunction Printer

Y3Z54A

Affected

Affected

006.2225A or higher

HP PageWide Pro 772dw Multifunction Printer

W1B31A

Affected

Affected

006.2225A or higher

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • HP Exploit Apache Log4J
  • Lexmark Apache Log4j Vulnerabilities
  • CVE-2021-39237
  • Log4j Papercut Vulnerability


See our Privacy Policy

1300 857 164     CONTACT US

Brisbane

RBC Group Brisbane

1 Mayneview Street
Milton QLD 4064

PO Box 199
Paddington QLD 4064

Gold Coast

RBC Group Gold Coast

1/22 Harvest Court
Southport QLD 4215

PO Box 4
Ashmore City LPO
Ashmore QLD 4214

Melbourne

RBC Group Melbourne

Unit 1, 20-22 Gardiners Rd
Notting Hill VIC 3168

Sydney

Interactive Australia

Tower B
39 Herbert St
St Leonards NSW 2065


Knowledge Base Software powered by Helpjuice

Definition by Author

0
0
Expand