First published: Mon Mar 09 2015(Updated: )
The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSToneIndicator.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2510.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Ole Point Of Sale Driver | <=1.13.001 | |
Hp Pos Keyboard Fk221aa | ||
Hp Pos Keyboard With Msr Fk218aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7890 is considered to be a critical vulnerability allowing arbitrary code execution.
To mitigate CVE-2014-7890, update the OLE Point of Sale drivers to version 1.13.003 or later.
CVE-2014-7890 affects systems using the OLE Point of Sale drivers prior to version 1.13.003 on HP Point of Sale Windows PCs.
CVE-2014-7890 enables remote attackers to execute arbitrary code on vulnerable systems.
CVE-2014-7890 specifically involves OPOSToneIndicator.ocx affecting HP Point of Sale hardware configurations.