HTTP: HP Point of Sale OPOS Driver Unsafe ActiveX Control

This signature detects attempts to use unsafe ActiveX controls in HP. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client application.

Extended Description

The OLE Point of Sale (OPOS) drivers before 1.13.003 on HP Point of Sale Windows PCs allow remote attackers to execute arbitrary code via vectors involving OPOSToneIndicator.ocx for POS keyboards and POS keyboards with MSR, aka ZDI-CAN-2510.

References

CVE: CVE-2014-7890

Short Name
HTTP:STC:ACTIVEX:HP-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2014-7890 Control Driver HP OPOS Point Sale Unsafe of
Release Date
03/25/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3834
False Positive
Unknown
CVSS Score

10.0

Found a potential security threat?