First published: Mon Mar 09 2015(Updated: )
The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSScanner.ocx for Imaging Barcode scanners, Linear Barcode scanners, Presentation Barcode scanners, Retail Integrated Barcode scanners, Wireless Barcode scanners, and 2D Value Wireless scanners.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP OLE Point of Sale Driver | <=1.13.001 | |
HP 2D Value Wireless Scanner | ||
HP Imaging Barcode Scanner BW868AA | ||
HP Linear Barcode Scanner QY405AA | ||
HP Presentation Barcode Scanner | ||
HP Retail Integrated Barcode Scanner E1L07AA | ||
HP Wireless Barcode Scanner E6P34AA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7897 has a high severity rating due to its potential for remote code execution.
To fix CVE-2014-7897, update the HP OLE Point of Sale driver to version 1.13.003 or later.
CVE-2014-7897 affects HP OLE Point of Sale drivers prior to version 1.13.003.
Yes, CVE-2014-7897 can be exploited remotely, allowing attackers to execute arbitrary code.
CVE-2014-7897 involves various types of imaging and barcode scanners used within HP Point of Sale systems.