Executive Summary

Summary
Title Hewlett-Packard printers and scanner devices allow remote firmware updates
Informations
Name VU#717921 First vendor Publication 2011-12-08
Vendor VU-CERT Last vendor Modification 2011-12-08
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#717921

Hewlett-Packard printers and scanner devices allow remote firmware updates

Overview

A vulnerability in certain Hewlett-Packard devices could allow a remote attacker to install unauthorized firmware on an affected system.

I. Description

Certain Hewlett-Packard Printers and Hewlett-Packard Digital Senders products allow the device's firmware to be updated over the network. The firmware update process can be accomplished via port 9100/tcp and does not require authentication. As a result, a remote attacker could perform unauthorized modification of the device's firmware.

Hewlett-Packard notes that the remote firmware update feature is enabled by default on affected systems. The list of affected devices can be found in HP Security Bulletin HPSBPI02728 SSRT100692, and includes many varieties of the HP LaserJet and Color LaserJet products.

II. Impact

A remote unauthenticated attacker could install malicious firmware on an affected device. This malicious firmware could allow the attacker to take control of the affected device, gain access to sensitive information sent to or from the device, or cause a denial of service (e.g., through malfunction of the device).

III. Solution

Disable Remote Firmware Update


HP has published guidance about securely configuring printers, including instructions about disabling the firmware update feature, in "HP Imaging and Printing Security Best Practices - Configuring Security for Multiple LaserJet MFPs and Color LaserJet MFPs".

Users are encouraged to review this document and take the appropriate actions to disable the firmware update feature.

Vendor Information

VendorStatusDate NotifiedDate Updated
Hewlett-Packard CompanyAffected2011-12-08

References

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449&jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0
http://h71028.www7.hp.com/enterprise/downloads/HP-Imaging10.pdf

Credit

This document was written by Chad Dougherty.

Other Information

Date Public:2011-11-29
Date First Published:2011-12-08
Date Last Updated:2011-12-08
CERT Advisory: 
CVE-ID(s):CVE-2011-4161
NVD-ID(s):CVE-2011-4161
US-CERT Technical Alerts: 
Severity Metric:0.00
Document Revision:9


This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Original Source

Url : http://www.kb.cert.org/vuls/id/717921

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 3
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1

Open Source Vulnerability Database (OSVDB)

Id Description
77420 HP Multiple LaserJet Printers / Digital Senders Remote Firmware Update (RFU) ...

Information Assurance Vulnerability Management (IAVM)

Date Description
2012-01-12 IAVM : 2012-B-0005 - HP Printers and Digital Senders Remote Firmware Update (RFU) Vulnerability
Severity : Category I - VMSKEY : V0031005