➢ This feature increases the number of allowed PIN users in the device's local
address book; from 1000 to 2000.
➢ Optimized JPEG decompression library improves performance of print jobs with
JPEG compressed images
➢ A new option has been added to delete the temporary jobs after 3 days.
➢ Error code “42.B0.01” will not be displayed in the event log for end customers.
➢ Added new feature to allow PCL 6 to suppress blank pages. Previously this feature
was only available with PCL5, now this functionality is also available with PCL6.
➢ Changes in power management to meet new Blue Angel regulations.
Embedded JetDirect:
➢ No New Updates
FIXES:
Security/Authentication:
➢ Resolved issue where aftermarket authentication agents utilizing the OXPd protocol
could inadvertently remove guest permissions to tabs (e.g. the Information tab) on
the EWS page.
➢ This firmware addresses the following security issue: CVE-2016-2183 – 3DES
TLS/SSL Birthday Attacks on 64-bit Block Ciphers (SWEET32) Vulnerability.
➢ Re-added web services (removed in FS 3.8) to allow HP Jet Advantage Security
Manager to manage the state of the Information tab in the embedded web server.
➢ Resolved redundant authentication prompts when accessing certain types of logs.
➢ This firmware addresses the following security issue: CVE-2017-2750 - Insecure
Solution DLL Signature Validation.
➢ Added support for G&D FIPS-201 SIPR smartcards that are provisioned without
encipherment certificates.
➢ When logging into the Embedded Web Server using Windows authentication, you
may not be able to see all the tabs or options that you have been granted access
to.
➢ This firmware addresses the following security issues: CVE-2017-13077:
Reinstallation of the pairwise encryption key (PTK-TK) in the 4-way handshake.
CVE-2017-13078: Reinstallation of the group key (GTK) in the 4-way handshake.
CVE-2017-13079: Reinstallation of the integrity group key (IGTK) in the 4-way
handshake. CVE-2017-13080: Reinstallation of the group key (GTK) in the group
key handshake. CVE-2017-13081: Reinstallation of the integrity group key (IGTK)
in the group key handshake.
➢ This firmware disables the "TFTP Configuration File" setting to prevent
unauthorized device resets.
Base: