CVE-2014-7890

HP OLE Point of Sale Driver < 1.13.001 - Remote Code Execution via OPOSToneIndicator.ocx

Title source: llm
STIX 2.1

Description

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSToneIndicator.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2510.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031840

Scores

EPSS 0.3008
EPSS Percentile 96.7%

Details

Status published
Products (1)
hp/ole_point_of_sale_driver < 1.13.001
Published Mar 09, 2015
Tracked Since Feb 18, 2026