¡¾Â©¶´Í¨¸æ¡¿HP ´òÓ¡»ú3Ô¶à¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´
Ðû²¼Ê±¼ä 2022-03-230x00 ©¶´¸ÅÊö
2022Äê3ÔÂ21ÈÕ£¬HP£¨»ÝÆÕ£©Ðû²¼Äþ¾²Í¨¸æ£¬ÆäÊý°ÙÖÖ´òÓ¡»úÐͺÅÖдæÔÚ¶à¸öÄþ¾²Â©¶´£¬¿Éµ¼ÖÂÐÅϢй¶¡¢¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£
0x01 ©¶´ÏêÇé
HPÕë¶ÔCVE-2022-3942ºÍÁíÍâ3¸ö©¶´·Ö±ðÐû²¼ÁËÄþ¾²Í¨¸æ£¬µ«ÕâЩ©¶´µÄÏêϸÐÅÏ¢ÉÐδÐû²¼£º
l CVE-2022-3942£ºHP´òÓ¡»úÔ¶³Ì´úÂëÖ´ÐЩ¶´
¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.4£¬HPµÄÑÏÖØÐÔÆÀ¼¶ÎªÑÏÖØ¡£Ä³Ð©»ÝÆÕ´òÓ¡²úÎïºÍÊý×Ö·¢ËͲúÎïÔÚʹÓÃLLMNR£¨Á´Â·µ±µØ¶à²¥Ãû³Æ½âÎö£©Ê±£¬ÈÝÒ×µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлò»º³åÇøÒç³öÎÊÌâ¡£
l CVE-2022-24291¡¢CVE-2022-24292¡¢CVE-2022-24293£ºHP´òÓ¡»úÖеÄÐÅϢй¶¡¢¾Ü¾ø·þÎñ¡¢Ô¶³Ì´úÂëÖ´ÐЩ¶´
ÆäÖУ¬CVE-2022-24291µÄCVSSÆÀ·ÖΪ7.5£¨¸ßΣ£©£¬CVE-2022-24292ºÍCVE-2022-24293µÄCVSSÆÀ·Ö¾ùΪ9.8£¨ÑÏÖØ£©¡£ÕâЩ©¶´Äܹ»µ¼ÖÂÐÅϢй¶¡¢¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÇÒ¾ùÎÞÐèÓû§½»»¥¼´¿É±»Ô¶³ÌÀûÓá£
Ó°Ï췶Χ
Êý°Ù¿î LaserJet Pro¡¢Pagewide Pro¡¢OfficeJet¡¢Enterprise¡¢Large Format ºÍ DeskJet µÈ´òÓ¡»úÐͺÅ
0x02 ´¦Öý¨Òé
ĿǰHPÒѾΪ´ó¶àÊýÊÜÓ°ÏìµÄ²úÎïÐû²¼Á˹̼þÄþ¾²¸üС£¼øÓÚ©¶´Ó°Ïì¹ã·º£¬ÊÜÓ°ÏìÓû§¿ÉÒÔ×Ô²é¸üдòÓ¡»ú¹Ì¼þ¡£
1.CVE-2022-3942µÄÊÜÓ°Ïì²úÎïÃû³Æ¡¢±àºÅ¼°¸üеĹ̼þ°æ±¾£¬Ïê¼ûHP¹Ù·½Í¨¸æ£º
https://support.hp.com/us-en/document/ish_5948778-5949142-16/
×¢£º¶ÔÓÚûÓпÉÓò¹¶¡µÄ´òÓ¡»ú²úÎ¿ÉÒÔÑ¡ÔñÔÚÍøÂçÉèÖÃÖнûÓà LLMNR¡£
2.CVE-2022-24291¡¢CVE-2022-24292ºÍCVE-2022-24293µÄÊÜÓ°Ïì²úÎïÃû³Æ¡¢±àºÅ¼°¸üеĹ̼þ°æ±¾£¬Ïê¼ûHP¹Ù·½Í¨¸æ£º
https://support.hp.com/us-en/document/ish_5950417-5950443-16/
ÏÂÔØÁ´½Ó£º
https://support.hp.com/us-en/drivers
0x03 ²Î¿¼Á´½Ó
https://support.hp.com/us-en/document/ish_5948778-5949142-16
https://www.bleepingcomputer.com/news/security/hundreds-of-hp-printer-models-vulnerable-to-remote-code-execution/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3942
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-03-23 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶«Éƽ̨¼ò½é
¶«Éƽ̨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º