CVE-2014-7890: Critical severity hp ole point of sale driver vulnerability
Published Mar 9, 2015
·Updated
The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSToneIndicator.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2510.
Affected Software
3 affected components
HP Ole Point Of Sale Driver<=1.13.001
HP Pos Keyboard Fk221aa
HP Pos Keyboard With Msr Fk218aa
Event History
Mar 9, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7890?
CVE-2014-7890 is considered to be a critical vulnerability allowing arbitrary code execution.
2
How do I fix CVE-2014-7890?
To mitigate CVE-2014-7890, update the OLE Point of Sale drivers to version 1.13.003 or later.
3
Who is affected by CVE-2014-7890?
CVE-2014-7890 affects systems using the OLE Point of Sale drivers prior to version 1.13.003 on HP Point of Sale Windows PCs.
4
What type of attack does CVE-2014-7890 enable?
CVE-2014-7890 enables remote attackers to execute arbitrary code on vulnerable systems.
5
What products are specifically involved in CVE-2014-7890?
CVE-2014-7890 specifically involves OPOSToneIndicator.ocx affecting HP Point of Sale hardware configurations.