PT-2010-5302 · Hewlett Packard · Hp Laserjet Mfp+7

Moritz Jodeit

·

Published

2010-11-17

·

Updated

2017-08-17

·

CVE-2010-4107

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers (affected versions not specified)
Description The default configuration of the PJL Access value in the File System External Access settings enables PJL commands that use the device's filesystem. This allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4107

Affected Products

Color Laserjet Mfp
Hp Laserjet Mfp
Laserjet 4100
Hp Laserjet 4200
Hp Laserjet 4300
Laserjet 5100
Laserjet 8150
Laserjet 9000