Executive Summary
Summary | |
---|---|
Title | Hewlett-Packard printers and scanner devices allow remote firmware updates |
Informations | |||
---|---|---|---|
Name | VU#717921 | First vendor Publication | 2011-12-08 |
Vendor | VU-CERT | Last vendor Modification | 2011-12-08 |
Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Vulnerability Note VU#717921Hewlett-Packard printers and scanner devices allow remote firmware updatesOverviewA vulnerability in certain Hewlett-Packard devices could allow a remote attacker to install unauthorized firmware on an affected system.I. DescriptionCertain Hewlett-Packard Printers and Hewlett-Packard Digital Senders products allow the device's firmware to be updated over the network. The firmware update process can be accomplished via port 9100/tcp and does not require authentication. As a result, a remote attacker could perform unauthorized modification of the device's firmware.Hewlett-Packard notes that the remote firmware update feature is enabled by default on affected systems. The list of affected devices can be found in HP Security Bulletin HPSBPI02728 SSRT100692, and includes many varieties of the HP LaserJet and Color LaserJet products. II. ImpactA remote unauthenticated attacker could install malicious firmware on an affected device. This malicious firmware could allow the attacker to take control of the affected device, gain access to sensitive information sent to or from the device, or cause a denial of service (e.g., through malfunction of the device).III. SolutionDisable Remote Firmware Update
Referenceshttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449&jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0 CreditThis document was written by Chad Dougherty. Other Information
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify |
Original Source
Url : http://www.kb.cert.org/vuls/id/717921 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 3 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 | |
Hardware | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
77420 | HP Multiple LaserJet Printers / Digital Senders Remote Firmware Update (RFU) ... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2012-01-12 | IAVM : 2012-B-0005 - HP Printers and Digital Senders Remote Firmware Update (RFU) Vulnerability Severity : Category I - VMSKEY : V0031005 |