hp-support-head-portlet

Acciones
Cargando...
Soporte al cliente de HP: base de conocimientos

hp-contact-secondary-navigation-portlet

Acciones
Cargando...

hp-share-print-widget-portlet

Acciones
Cargando...
  • Información
    Más información sobre cómo actualizar a Windows 11

    Guía de actualización a Windows 11

    Información

    Arregle y solucione problemas de actualización de Windows 10 en una Computadora o Impresora HP. Haga clic aquí

    Información

    ¿Problemas de audio o sonido? ¡Pruebe nuestro automatizado HP Audio check!

  • Comentarios

hp-concentra-wrapper-portlet

Acciones
Cargando...

SUPPORT COMMUNICATION- SECURITY BULLETIN

ID de documento: c05872536

Versión: 1

HP Printing Security Advisory - KRACK Attacks Potential Vulnerabilities

Notice:: The information in this security bulletin should be acted upon as soon as possible.

Fecha de publicación : 09-Jan-2018

Última actualización : 09-Jan-2018

Potential Security Impact:
KRACK Attacks

RESUMEN DE VULNERABILIDADES
On October 16, security researchers publicly announced vulnerabilities in the WiFi WPA2 standard. See the References section below for links to additional resources describing the KRACK Attacks WPA2 potential vulnerabilities in detail.
The HP printing devices and networking accessories listed below are susceptible to the applicable vulnerabilities (CVE) noted in the References section below. However, the vulnerabilities described in the CVEs can be mitigated for each of these devices and accessories as set forth in the Workarounds section below.
  • HP LaserJet Enterprise printers and multifunction printers
  • HP LaserJet Managed printers and multifunction printers
  • HP LaserJet Pro printers and multifunction printers
  • HP PageWide Enterprise printers and multifunction printers
  • HP PageWide Pro printers and multifunction printers
  • HP OfficeJet Enterprise series printers and multifunction printers
  • HP OfficeJet Pro printers and multifunction printers
  • HP Inkjet (DeskJet, Envy, PhotoSmart) printers and multifunction printers
  • HP DesignJet large format printers
  • HP JetDirect wireless print server accessories
Número de referencia
  1. www.krackattacks.com – Vulnerability information website.
  2. CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.
  3. CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.
  4. CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way handshake.
  5. CVE-2017-13080: Reinstallation of the group key (GTK) in the group key handshake.
  6. CVE-2017-13081: Reinstallation of the integrity group key (IGTK) in the group key handshake.
VERSIONES DE SOFTWARE COMPATIBLES*: SOLO se incluyen las versiones afectadas.
N/A
ANTECEDENTES
N/A
RESOLUCIÓN
Customers may mitigate risk for the identified vulnerabilities through one of the methods listed below. Devices vary in configuration procedures, so please refer to the product user guide for specific instructions.
  • Do not use unpatched clients to connect to the print device Wi-Fi Direct network. Wi-Fi Direct implementation is not impacted, but unpatched mobile devices could be subject to attack when connecting to Wi-Fi Direct
  • Configure the wireless access point or printer to only allow WPA2-AES/CCMP mode, thus disabling WPA-TKIP
  • Use only TLS enabled protocols to communicate with the printer
  • Turning off printer Wi-Fi and using Ethernet or USB
What can you do?
Subscribe to HP real-time security information: All HP products use a common centralized Security Bulletin process managed by HP´s Product Security Response Team (PSRT). Subscribe to HP Security Bulletins by following these steps:
  1. Click Get software and drivers.
  2. Find your product.
  3. Scroll to the bottom of the page and under Other support resources, click Sign up for driver, support & security alerts.
  4. Follow the onscreen prompts to sign up for alerts.
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.

"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin.HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action.HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin.To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
HISTORIAL DE REVISIONES : Rev.DateReason1.024‐October‐2017Initial Version

HP Inc. shall not be liable for technical or editorial errors or omissions contained herein.The information provided is provided "as is" without warranty of any kind.To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration.The information in this document is subject to change without notice.HP Inc. and the names of HP products referenced herein are trademarks of HP Inc. in the United States and other countries.Other product and company names mentioned herein may be trademarks of their respective owners.

hp-feedback-input-portlet

Acciones
Cargando...

hp-feedback-banner-portlet

Acciones
Cargando...

hp-country-locator-portlet

Acciones
Cargando...
País/región: Flag Uruguay

hp-detect-load-my-device-portlet

Acciones
Cargando...