Lucene search

K
cveHpCVE-2010-4107
HistoryNov 17, 2010 - 4:00 p.m.

CVE-2010-4107

2010-11-1716:00:02
CWE-22
hp
web.nvd.nist.gov
54
hp
laserjet
mfp
printers
security
vulnerability
cve-2010-4107
filesystem
remote attack
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.09

Percentile

94.6%

The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device’s filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

Affected configurations

Nvd
Node
hp9000
OR
hpcolor_laserjet_mfp
OR
hplaserjet_4100
OR
hplaserjet_4200
OR
hplaserjet_4300
OR
hplaserjet_5100
OR
hplaserjet_8150
OR
hplaserjet_mfp
VendorProductVersionCPE
hplaserjet_4300cpe:/h:hp:laserjet_4300::::
hplaserjet_4200cpe:/h:hp:laserjet_4200::::
hplaserjet_8150cpe:/h:hp:laserjet_8150::::
hp9000cpe:/h:hp:9000::::
hpcolor_laserjet_mfpcpe:/h:hp:color_laserjet_mfp::::
hplaserjet_mfpcpe:/h:hp:laserjet_mfp::::
hplaserjet_4100cpe:/h:hp:laserjet_4100::::
hplaserjet_5100cpe:/h:hp:laserjet_5100::::

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.09

Percentile

94.6%