CVE-2013-6427: Code Injection
upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6427?
CVE-2013-6427 has a medium severity level due to its potential to allow remote code execution through man-in-the-middle attacks.
How do I fix CVE-2013-6427?
To fix CVE-2013-6427, upgrade to HPLIP version 3.13.11 or later, which addresses this vulnerability.
What types of attacks does CVE-2013-6427 expose systems to?
CVE-2013-6427 exposes systems to man-in-the-middle attacks that can lead to arbitrary code execution.
Which software versions are affected by CVE-2013-6427?
CVE-2013-6427 affects HP Linux Imaging and Printing (HPLIP) versions 3.9.2 through 3.13.10.
Is there a workaround for CVE-2013-6427?
Currently, there are no official workarounds for CVE-2013-6427 other than updating to a patched version of HPLIP.