← All CVEs

CVE-2014-7892

high · 10

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMSR.ocx for Mini MSR magnetic stripe readers, Retail Integrated Dual-Head MSR magnetic stripe readers, Integrated Single Head MSR w/o SRED magnetic stripe readers, Integrated Single Head w/o MSR SRED magnetic stripe readers, RP7 Single Head MSR w/o SRED magnetic stripe readers, POS keyboards, and POS keyboards with MSR, aka ZDI-CAN-2508.

10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2015-03-09
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
hpole_point_of_sale_driver<= 1.13.001
hpintegrated_single_head_msr_w/o_sred_j1a33aaall versions
hpintegrated_single_head_w/o_msr_sred_j1a34aaall versions
hpmini_msr_fk186aaall versions
hppos_keyboard_fk221aaall versions
hppos_keyboard_with_msr_fk218aaall versions
hpretail_integrated_dual-head_msr_qz673aaall versions
hprp7_single_head_msr_w/o_sred_k1k15aaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7892