Home

Description

The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inherited under certain conditions —e.g., when an NFC device (such as a smartphone/smartwatches) is in proximity during a card swipe event.

PUBLISHED Reserved 2025-10-20 | Published 2025-10-30 | Updated 2025-10-30 | Assigner hp




MEDIUM: 6.8CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unknown

1.0 (custom)
affected

References

support.hp.com/...ument/ish_13175687-13175716-16/hpsbpi04065

cve.org (CVE-2025-11998)

nvd.nist.gov (CVE-2025-11998)

Download JSON