Cyber Posture

CVE-2025-2268

High

Published: 14 March 2025

Published
14 March 2025
Modified
16 January 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0039 60.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.

Security Summary

CVE-2025-2268 is a denial-of-service vulnerability affecting the HP LaserJet MFP M232-M237 Printer Series. The issue arises when a specially crafted request message is sent via the Internet Printing Protocol (IPP), potentially disrupting printer functionality. Published on 2025-03-14, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is linked to CWE-241.

Remote attackers can exploit this vulnerability over the network with low complexity, requiring no privileges, authentication, or user interaction. By transmitting a malicious IPP request to an affected printer, an attacker can cause a denial of service, severely impacting availability while leaving confidentiality and integrity unaffected.

HP has issued a security bulletin detailing the vulnerability at https://support.hp.com/us-en/document/ish_12114154-12114176-16/hpsbpi04013, which security practitioners should consult for patch availability and mitigation guidance.

Details

CWE(s)
CWE-241

Affected Products

hp
6gx09a firmware
≤ 2025-03-24
hp
6gx09e firmware
≤ 2025-03-24
hp
9yf91e firmware
≤ 2025-03-24
hp
9yg02e firmware
≤ 2025-03-24
hp
9yg05e firmware
≤ 2025-03-24
hp
6gw71a firmware
≤ 2025-03-24
hp
6gw99a firmware
≤ 2025-03-24
hp
6gx00a firmware
≤ 2025-03-24
hp
6gx03a firmware
≤ 2025-03-24
hp
6gx04a firmware
≤ 2025-03-24
+44 more product configuration(s) — see NVD for full list

MITRE ATT&CK Enterprise Techniques

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

The vulnerability enables remote exploitation of a software flaw in IPP handling to crash or disrupt the printer service, directly matching T1499.004 Application or System Exploitation for denying availability.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References