CVE-2014-7892
The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMSR.ocx for Mini MSR magnetic stripe readers, Retail Integrated Dual-Head MSR magnetic stripe readers, Integrated Single Head MSR w/o SRED magnetic stripe readers, Integrated Single Head w/o MSR SRED magnetic stripe readers, RP7 Single Head MSR w/o SRED magnetic stripe readers, POS keyboards, and POS keyboards with MSR, aka ZDI-CAN-2508.
Published:Mar 9, 2015
Last Modified:Apr 12, 2025
EPS:Mar 9, 2015
EPSS Score:0.28809
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Hp
Product
Integrated Single Head Msr W\/o Sred J1a33aa
Hp
Integrated Single Head Msr W\/o Sred J1a33aa
Vendor
Hp
Product
Integrated Single Head W\/o Msr Sred J1a34aa
Hp
Integrated Single Head W\/o Msr Sred J1a34aa
Vendor
Hp
Product
Mini Msr Fk186aa
Hp
Mini Msr Fk186aa
Vendor
Hp
Product
Ole Point Of Sale Driver
Hp
Ole Point Of Sale Driver
Vendor
Hp
Product
Pos Keyboard Fk221aa
Hp
Pos Keyboard Fk221aa
Vendor
Hp
Product
Pos Keyboard With Msr Fk218aa
Hp
Pos Keyboard With Msr Fk218aa
Vendor
Hp
Product
Retail Integrated Dual-head Msr Qz673aa
Hp
Retail Integrated Dual-head Msr Qz673aa
Vendor
Hp
Product
Rp7 Single Head Msr W\/o Sred K1k15aa
Hp
Rp7 Single Head Msr W\/o Sred K1k15aa
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
