CVE-2020-28416
📋 TL;DR
This vulnerability in HP's I.R.I.S. OCR software allows local attackers to execute arbitrary code on affected HP printers. It affects users of HP PageWide and OfficeJet printers with vulnerable software installations. Exploitation requires local access to the printer system.
💻 Affected Systems
- HP PageWide printers
- HP OfficeJet printers
📦 What is this software?
Officejet Pro 6830 E3e02a Firmware by Hp
View all CVEs affecting Officejet Pro 6830 E3e02a Firmware →
Officejet Pro 6830 M0f56a Firmware by Hp
View all CVEs affecting Officejet Pro 6830 M0f56a Firmware →
Officejet Pro 6830c L3l04a Firmware by Hp
View all CVEs affecting Officejet Pro 6830c L3l04a Firmware →
Officejet Pro 6835 J2d37a Firmware by Hp
View all CVEs affecting Officejet Pro 6835 J2d37a Firmware →
Officejet Pro 6960 J7k33a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 J7k33a Firmware →
Officejet Pro 6960 J7k35a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 J7k35a Firmware →
Officejet Pro 6960 J7k37a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 J7k37a Firmware →
Officejet Pro 6960 J7k38a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 J7k38a Firmware →
Officejet Pro 6960 J7k39a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 J7k39a Firmware →
Officejet Pro 6960 T0f28a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f28a Firmware →
Officejet Pro 6960 T0f30a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f30a Firmware →
Officejet Pro 6960 T0f31a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f31a Firmware →
Officejet Pro 6960 T0f32a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f32a Firmware →
Officejet Pro 6960 T0f36a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f36a Firmware →
Officejet Pro 6960 T0f38a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0f38a Firmware →
Officejet Pro 6960 T0g25a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0g25a Firmware →
Officejet Pro 6960 T0g26a Firmware by Hp
View all CVEs affecting Officejet Pro 6960 T0g26a Firmware →
Officejet Pro 6970 J7k34a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 J7k34a Firmware →
Officejet Pro 6970 J7k36a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 J7k36a Firmware →
Officejet Pro 6970 J7k40a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 J7k40a Firmware →
Officejet Pro 6970 J7k41a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 J7k41a Firmware →
Officejet Pro 6970 J7k42a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 J7k42a Firmware →
Officejet Pro 6970 T0f29a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f29a Firmware →
Officejet Pro 6970 T0f33a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f33a Firmware →
Officejet Pro 6970 T0f34a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f34a Firmware →
Officejet Pro 6970 T0f35a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f35a Firmware →
Officejet Pro 6970 T0f37a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f37a Firmware →
Officejet Pro 6970 T0f39a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f39a Firmware →
Officejet Pro 6970 T0f40a Firmware by Hp
View all CVEs affecting Officejet Pro 6970 T0f40a Firmware →
Officejet Pro 7740 G5j38a Firmware by Hp
View all CVEs affecting Officejet Pro 7740 G5j38a Firmware →
Officejet Pro 7745 T1p99a Firmware by Hp
View all CVEs affecting Officejet Pro 7745 T1p99a Firmware →
Officejet Pro 8710 D9l18a Firmware by Hp
View all CVEs affecting Officejet Pro 8710 D9l18a Firmware →
Officejet Pro 8710 J6x79a Firmware by Hp
View all CVEs affecting Officejet Pro 8710 J6x79a Firmware →
Officejet Pro 8710 M9l66a Firmware by Hp
View all CVEs affecting Officejet Pro 8710 M9l66a Firmware →
Officejet Pro 8710 M9l67a Firmware by Hp
View all CVEs affecting Officejet Pro 8710 M9l67a Firmware →
Officejet Pro 8712 T0g46a Firmware by Hp
View all CVEs affecting Officejet Pro 8712 T0g46a Firmware →
Officejet Pro 8715 J6x76a Firmware by Hp
View all CVEs affecting Officejet Pro 8715 J6x76a Firmware →
Officejet Pro 8715 J6x78a Firmware by Hp
View all CVEs affecting Officejet Pro 8715 J6x78a Firmware →
Officejet Pro 8715 J6x80a Firmware by Hp
View all CVEs affecting Officejet Pro 8715 J6x80a Firmware →
Officejet Pro 8715 K7s37a Firmware by Hp
View all CVEs affecting Officejet Pro 8715 K7s37a Firmware →
Officejet Pro 8715 M9l70a Firmware by Hp
View all CVEs affecting Officejet Pro 8715 M9l70a Firmware →
Officejet Pro 8716 J6x77a Firmware by Hp
View all CVEs affecting Officejet Pro 8716 J6x77a Firmware →
Officejet Pro 8716 J6x81a Firmware by Hp
View all CVEs affecting Officejet Pro 8716 J6x81a Firmware →
Officejet Pro 8717 K7s38a Firmware by Hp
View all CVEs affecting Officejet Pro 8717 K7s38a Firmware →
Officejet Pro 8717 M9l65a Firmware by Hp
View all CVEs affecting Officejet Pro 8717 M9l65a Firmware →
Officejet Pro 8718 T0g47a Firmware by Hp
View all CVEs affecting Officejet Pro 8718 T0g47a Firmware →
Officejet Pro 8718 T0g48a Firmware by Hp
View all CVEs affecting Officejet Pro 8718 T0g48a Firmware →
Officejet Pro 8719 T0g49a Firmware by Hp
View all CVEs affecting Officejet Pro 8719 T0g49a Firmware →
Officejet Pro 8720 D9l19a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 D9l19a Firmware →
Officejet Pro 8720 K7s35a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 K7s35a Firmware →
Officejet Pro 8720 K7s36a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 K7s36a Firmware →
Officejet Pro 8720 M9l74a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 M9l74a Firmware →
Officejet Pro 8720 M9l75a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 M9l75a Firmware →
Officejet Pro 8720 M9l76a Firmware by Hp
View all CVEs affecting Officejet Pro 8720 M9l76a Firmware →
Officejet Pro 8725 J7a28a Firmware by Hp
View all CVEs affecting Officejet Pro 8725 J7a28a Firmware →
Officejet Pro 8725 J7a31a Firmware by Hp
View all CVEs affecting Officejet Pro 8725 J7a31a Firmware →
Officejet Pro 8725 K7s34a Firmware by Hp
View all CVEs affecting Officejet Pro 8725 K7s34a Firmware →
Officejet Pro 8725 M9l80a Firmware by Hp
View all CVEs affecting Officejet Pro 8725 M9l80a Firmware →
Officejet Pro 8727 J7a29a Firmware by Hp
View all CVEs affecting Officejet Pro 8727 J7a29a Firmware →
Officejet Pro 8728 T0g54a Firmware by Hp
View all CVEs affecting Officejet Pro 8728 T0g54a Firmware →
Officejet Pro 8732m T0g56a Firmware by Hp
View all CVEs affecting Officejet Pro 8732m T0g56a Firmware →
Officejet Pro 8732m T0g57a Firmware by Hp
View all CVEs affecting Officejet Pro 8732m T0g57a Firmware →
Officejet Pro 8732m T0g58a Firmware by Hp
View all CVEs affecting Officejet Pro 8732m T0g58a Firmware →
Officejet Pro 8732m T0g59a Firmware by Hp
View all CVEs affecting Officejet Pro 8732m T0g59a Firmware →
Officejet Pro 8740 D9l21a Firmware by Hp
View all CVEs affecting Officejet Pro 8740 D9l21a Firmware →
Officejet Pro 8740 K7s42a Firmware by Hp
View all CVEs affecting Officejet Pro 8740 K7s42a Firmware →
Officejet Pro 8743 T0g65a Firmware by Hp
View all CVEs affecting Officejet Pro 8743 T0g65a Firmware →
Officejet Pro 8744 K7s39a Firmware by Hp
View all CVEs affecting Officejet Pro 8744 K7s39a Firmware →
Officejet Pro 8745 J6x83a Firmware by Hp
View all CVEs affecting Officejet Pro 8745 J6x83a Firmware →
Officejet Pro 8745 K7s43a Firmware by Hp
View all CVEs affecting Officejet Pro 8745 K7s43a Firmware →
Officejet Pro 8746 K7s40a Firmware by Hp
View all CVEs affecting Officejet Pro 8746 K7s40a Firmware →
Officejet Pro 8747 K7s41a Firmware by Hp
View all CVEs affecting Officejet Pro 8747 K7s41a Firmware →
Pagewide Managed P52750dw J9v78b Firmware by Hp
View all CVEs affecting Pagewide Managed P52750dw J9v78b Firmware →
Pagewide Managed P57750dw 9v82a Firmware by Hp
View all CVEs affecting Pagewide Managed P57750dw 9v82a Firmware →
Pagewide Managed P57750dw J9v82b Firmware by Hp
View all CVEs affecting Pagewide Managed P57750dw J9v82b Firmware →
Pagewide Managed P57750dw J9v82c Firmware by Hp
View all CVEs affecting Pagewide Managed P57750dw J9v82c Firmware →
Pagewide Managed P57750dw J9v82d Firmware by Hp
View all CVEs affecting Pagewide Managed P57750dw J9v82d Firmware →
Pagewide Pro 477dn D3q19a Firmware by Hp
View all CVEs affecting Pagewide Pro 477dn D3q19a Firmware →
Pagewide Pro 477dn D3q19b Firmware by Hp
View all CVEs affecting Pagewide Pro 477dn D3q19b Firmware →
Pagewide Pro 477dn D3q19d Firmware by Hp
View all CVEs affecting Pagewide Pro 477dn D3q19d Firmware →
Pagewide Pro 477dw D3q20a Firmware by Hp
View all CVEs affecting Pagewide Pro 477dw D3q20a Firmware →
Pagewide Pro 477dw D3q20b Firmware by Hp
View all CVEs affecting Pagewide Pro 477dw D3q20b Firmware →
Pagewide Pro 477dw D3q20c Firmware by Hp
View all CVEs affecting Pagewide Pro 477dw D3q20c Firmware →
Pagewide Pro 477dw D3q20d Firmware by Hp
View all CVEs affecting Pagewide Pro 477dw D3q20d Firmware →
Pagewide Pro 477dw W2z53b Firmware by Hp
View all CVEs affecting Pagewide Pro 477dw W2z53b Firmware →
Pagewide Pro 577dw D3q21a Firmware by Hp
View all CVEs affecting Pagewide Pro 577dw D3q21a Firmware →
Pagewide Pro 577dw D3q21b Firmware by Hp
View all CVEs affecting Pagewide Pro 577dw D3q21b Firmware →
⚠️ Risk & Real-World Impact
Worst Case
Complete compromise of the printer system allowing persistent malware installation, data exfiltration, and lateral movement to connected networks.
Likely Case
Local privilege escalation leading to unauthorized access to printer functions, configuration changes, and potential data capture from scanned documents.
If Mitigated
Limited impact with proper network segmentation and access controls preventing unauthorized local access to printer interfaces.
🎯 Exploit Status
Requires local access to printer system. No public exploit code available as of advisory publication.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Update to latest firmware/software version as specified in HP advisory
Vendor Advisory: https://support.hp.com/us-en/document/c07051163
Restart Required: Yes
Instructions:
1. Visit HP support site and download latest firmware/software update for your printer model. 2. Install update following HP's instructions. 3. Restart printer to complete installation.
🔧 Temporary Workarounds
Disable I.R.I.S. OCR software
allRemove or disable the vulnerable OCR component if not required for operations
Follow printer administration interface to disable OCR features
Restrict local access
allImplement network segmentation and access controls to limit who can access printer management interfaces
Configure firewall rules to restrict printer management port access
Implement VLAN segmentation for printers
🧯 If You Can't Patch
- Segment printers on isolated network VLANs
- Implement strict access controls to printer management interfaces
- Disable unnecessary printer features including OCR if not required
🔍 How to Verify
Check if Vulnerable:
Check printer firmware version against HP's advisory. If I.R.I.S. OCR software is installed and not updated, system is vulnerable.
Check Version:
Check printer web interface or control panel for firmware version information
Verify Fix Applied:
Verify firmware version has been updated to latest version specified in HP advisory. Confirm OCR software version if possible.
📡 Detection & Monitoring
Log Indicators:
- Unusual OCR process activity
- Unauthorized configuration changes
- Unexpected software installations on printer
Network Indicators:
- Unusual network traffic from printer to unexpected destinations
- Suspicious connections to printer management ports
SIEM Query:
source="printer_logs" AND (event="configuration_change" OR event="software_install")