Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-7897


The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSScanner.ocx for Imaging Barcode scanners, Linear Barcode scanners, Presentation Barcode scanners, Retail Integrated Barcode scanners, Wireless Barcode scanners, and 2D Value Wireless scanners.


Published

2015-03-09T17:59:08.500

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hp ole_point_of_sale_driver ≤ 1.13.001 Yes
Hardware hp 2d_value_wireless_scanner_k3l28aa * No
Hardware hp imaging_barcode_scanner_bw868aa * No
Hardware hp linear_barcode_scanner_qy405aa * No
Hardware hp presentation_barcode_scanner_qy439aa * No
Hardware hp retail_integrated_barcode_scanner_e1l07aa * No
Hardware hp wireless_barcode_scanner_e6p34aa * No

References