PT-2010-5302 · Hewlett Packard · Hp Laserjet Mfp+7
Moritz Jodeit
·
Published
2010-11-17
·
Updated
2017-08-17
·
CVE-2010-4107
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers (affected versions not specified)
Description
The default configuration of the PJL Access value in the File System External Access settings enables PJL commands that use the device's filesystem. This allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Color Laserjet Mfp
Hp Laserjet Mfp
Laserjet 4100
Hp Laserjet 4200
Hp Laserjet 4300
Laserjet 5100
Laserjet 8150
Laserjet 9000