CVE-2024-5749

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Oct 15, 2024
Updated: Oct 16, 2024
CWE ID 1262

Summary

CVE-2024-5749 is a newly disclosed vulnerability affecting select HP DesignJet models. This issue permits an attacker to reflect SMTP server credentials, potentially exposing sensitive information. The flaw arises due to insufficient security measures in the products' handling of SMTP communication. An attacker can exploit this vulnerability by intercepting SMTP traffic and reflecting back the credentials to the attacker's control. To mitigate the risk, HP urges users to update their DesignJet products with the latest security patches promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share