Security/Authentication:
➢ Resolved issue where aftermarket authentication agents utilizing the OXPd protocol
could inadvertently remove guest permissions to tabs (e.g. the Information tab) on
the EWS page.
➢ "This firmware addresses the following security issue:
➢ CVE-2016-2183 – 3DES TLS/SSL Birthday Attacks on 64-bit Block Ciphers
(SWEET32) Vulnerability."
➢ Re-added web services (removed in FS 3.8) to allow HP Jet Advantage Security
Manager to manage the state of the Information tab in the embedded web server.
➢ Resolved redundant authentication prompts when accessing certain types of logs.
➢ This firmware addresses the following security issue: CVE-2017-2750 - Insecure
Solution DLL Signature Validation.
➢ Added support for G&D FIPS-201 SIPR smartcards that are provisioned without
encipherment certificates.
➢ When logging into the Embedded Web Server using Windows authentication, you
may not be able to see all the tabs or options that you have been granted access
to.
➢ This firmware addresses the following security issues:
CVE-2017-13077: Reinstallation of the pairwise encryption key (PTK-TK) in the 4way handshake. CVE-2017-13078: Reinstallation of the group key (GTK) in the 4way handshake. CVE-2017-13079: Reinstallation of the integrity group key (IGTK)
in the 4-way handshake. CVE-2017-13080: Reinstallation of the group key (GTK)
in the group key handshake. CVE-2017-13081: Reinstallation of the integrity
group key (IGTK) in the group key handshake.
➢ This firmware disables the "TFTP Configuration File" setting to prevent
unauthorized device resets.
Embedded JetDirect:
➢ Fixed "IP Address/Subnet is out of range. Check the field. IP=x.x.x.x
Mask=x.x.x.x" error given when an IP address was entered with zero for the host
number in the Access Control List.
➢ Buffers expanded to hold large DNS responses (70+ records). Previously only
about 7 or 8 records were accepted.
➢ Trying to connect via the FTP may fail with certain applications.
➢ Fixed an issue where Windows Authentication would hang the printer.
➢ Product was generating Certificate Signing Requests with version number other
than zero. RFC 2986 requires a version number of zero.
➢ Product was generating Certificate Signing Requests with version number other
than zero. RFC 2986 requires a version number of zero.
➢ Printer crashes with 81.09.00 Embedded Jetdirect Error message when user sets
Admin password from Telnet.
➢ Under certain circumstances during initial power-on, the DCHP Discover message
is sent without a hostname (option 81). This fix ensures that option 81 is always
present when applicable.