CVE-2011-4161

HP Color LaserJet and Digital Sender - Remote Code Execution via Firmware Update

Title source: llm
STIX 2.1

Description

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

References (8)

Core 8
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/717921
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47063
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026357
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51324

Scores

EPSS 0.1599
EPSS Percentile 94.9%

Details

CWE
CWE-264
Status published
Products (43)
hp/color_laserjet_3000
hp/color_laserjet_3800
hp/color_laserjet_4700
hp/color_laserjet_4730 mfp
hp/color_laserjet_4730_mfp
hp/color_laserjet_5550
hp/color_laserjet_9500
hp/color_laserjet_cm3530
hp/color_laserjet_cm4540 mfp
hp/color_laserjet_cm4730 mfp
... and 33 more
Published Dec 01, 2011
Tracked Since Feb 18, 2026