← All CVEs

CVE-2014-7895

high · 10

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSCashDrawer.ocx for PUSB Thermal Receipt printers, SerialUSB Thermal Receipt printers, Hybrid POS printers with MICR, Value PUSB Receipt printers, Value Serial/USB Receipt printers, and USB Standard Duty cash drawers, aka ZDI-CAN-2505.

10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2015-03-09
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
hpole_point_of_sale_driver<= 1.13.001
hphybrid_pos_printer_with_micr_us_fk184aaall versions
hppusb_thermal_receipt_printer_f7m67aaall versions
hppusb_thermal_receipt_printer_fk224aaall versions
hpserialusb_thermal_receipt_printer_bm476aaall versions
hpusb_standard_duty_cash_drawer_e8e45aaall versions
hpvalue_serial/usb_receipt_printer_f7m66aaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7895