CVE-2014-7892

HP OLE Point of Sale Driver < 1.13.001 - Remote Code Execution via OPOSMSR.ocx

Title source: manual
STIX 2.1

Description

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSMSR.ocx for Mini MSR magnetic stripe readers, Retail Integrated Dual-Head MSR magnetic stripe readers, Integrated Single Head MSR w/o SRED magnetic stripe readers, Integrated Single Head w/o MSR SRED magnetic stripe readers, RP7 Single Head MSR w/o SRED magnetic stripe readers, POS keyboards, and POS keyboards with MSR, aka ZDI-CAN-2508.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031840

Scores

EPSS 0.2881
EPSS Percentile 96.6%

Details

Status published
Products (1)
hp/ole_point_of_sale_driver < 1.13.001
Published Mar 09, 2015
Tracked Since Feb 18, 2026