CVE-2025-43023 Details
Description
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).
A potential security vulnerability exists in the HP Linux Imaging and Printing Software due to the use of a weak code signing key with the Digital Signature Algorithm (DSA). This vulnerability is documented in the HP Security Bulletin HPSBPI04033.
Users can update to HP Linux Imaging and Printing version 3.25.2. This version is available for download from the HP Linux Imaging and Printing website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/08/22/4 | CVE | Mailing ListThird Party Advisory |
| https://support.hp.com/us-en/document/ish_12804224-12804228-16/hpsbpi04033 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hp linux imaging and printing | < 3.25.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 16, 2026 | Initial Analysis | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Jul 28, 2025 | New CVE Received | [email protected] |