CVE-2023-4063: Medium severity HP OfficeJet Pro vulnerability

Published Mar 22, 2024
·
Updated

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

Affected Software

85 affected components
HP OfficeJet Pro
All of the following
HP 1kr42a Firmware<002.2349a
HP 1kr42a
All of the following
HP 1kr45a Firmware<002.2349a
HP 1kr45a
All of the following
HP 1kr46a Firmware<002.2349a
HP 1kr46a
All of the following
HP 1kr48a Firmware<002.2349a
HP 1kr48a
All of the following
HP 1kr49a Firmware<002.2349a
HP 1kr49a
All of the following
HP 1kr54a Firmware<002.2349a
HP 1kr54a
All of the following
HP 1kr55a Firmware<002.2349a
HP 1kr55a
All of the following
HP 1kr55b Firmware<002.2349a
HP 1kr55b
All of the following
HP 1kr55d Firmware<002.2349a
HP 1kr55d
All of the following
HP 1mr66a Firmware<002.2349a
HP 1mr66a
All of the following
HP 1mr67a Firmware<002.2349a
HP 1mr67a
All of the following
HP 1mr68a Firmware<002.2349a
HP 1mr68a
All of the following
HP 1mr69a Firmware<002.2349a
HP 1mr69a
All of the following
HP 1mr69c Firmware<002.2349a
HP 1mr69c
All of the following
HP 1mr70a Firmware<002.2349a
HP 1mr70a
All of the following
HP 1mr71a Firmware<002.2349a
HP 1mr71a
All of the following
HP 1mr72a Firmware<002.2349a
HP 1mr72a
All of the following
HP 1mr73a Firmware<002.2349a
HP 1mr73a
All of the following
HP 1mr73d Firmware<002.2349a
HP 1mr73d
All of the following
HP 1mr74a Firmware<002.2349a
HP 1mr74a
All of the following
HP 1mr75a Firmware<002.2349a
HP 1mr75a
All of the following
HP 1mr76a Firmware<002.2349a
HP 1mr76a
All of the following
HP 1mr77a Firmware<002.2349a
HP 1mr77a
All of the following
HP 1mr78a Firmware<002.2349a
HP 1mr78a
All of the following
HP 1mr78b Firmware<002.2349a
HP 1mr78b
All of the following
HP 1mr79a Firmware<002.2349a
HP 1mr79a
All of the following
HP 1mr80d Firmware<002.2349a
HP 1mr80d
All of the following
HP 3uk83a Firmware<002.2349a
HP 3uk83a
All of the following
HP 3uk83b Firmware<002.2349a
HP 3uk83b
All of the following
HP 3uk84a Firmware<002.2349a
HP 3uk84a
All of the following
HP 3uk85d Firmware<002.2349a
HP 3uk85d
All of the following
HP 3uk86b Firmware<002.2349a
HP 3uk86b
All of the following
HP 3uk90d Firmware<002.2349a
HP 3uk90d
All of the following
HP 3uk91b Firmware<002.2349a
HP 3uk91b
All of the following
HP 3uk93d Firmware<002.2349a
HP 3uk93d
All of the following
HP 3uk96d Firmware<002.2349a
HP 3uk96d
All of the following
HP 3uk97d Firmware<002.2349a
HP 3uk97d
All of the following
HP 3uk98d Firmware<002.2349a
HP 3uk98d
All of the following
HP 3uk99d Firmware<002.2349a
HP 3uk99d
All of the following
HP 3ul00d Firmware<002.2349a
HP 3ul00d
All of the following
HP 3ul05b Firmware<002.2349a
HP 3ul05b
All of the following
HP Y8m28d Firmware<002.2349a
HP Y8m28d

Event History

Mar 22, 2024
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-4063?

CVE-2023-4063 has been classified as a Denial of Service vulnerability which can affect the availability of certain HP OfficeJet Pro printers.

2

How do I fix CVE-2023-4063?

To fix CVE-2023-4063, ensure that your printer firmware is updated to the latest version provided by HP.

3

Which printers are affected by CVE-2023-4063?

CVE-2023-4063 affects certain models of HP OfficeJet Pro printers when processing improper eSCL URL GET requests.

4

What type of attack does CVE-2023-4063 enable?

CVE-2023-4063 enables a Denial of Service attack, potentially causing the printer to become unresponsive.

5

Is there a workaround for CVE-2023-4063?

Currently, the recommended approach for CVE-2023-4063 is to apply the official firmware updates from HP as there are no specified workarounds.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203