CVE Vulnerabilities

CVE-2011-4161

Published: Dec 01, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

Affected Software

NameVendorStart VersionEnd Version
Color_laserjet_3000Hp**
Color_laserjet_3800Hp**
Color_laserjet_4700Hp**
Color_laserjet_4730Hpmfp (including)mfp (including)
Color_laserjet_4730_mfpHp**
Color_laserjet_5550Hp**
Color_laserjet_9500Hp**
Color_laserjet_cm3530Hp**
Color_laserjet_cm4540Hpmfp (including)mfp (including)
Color_laserjet_cm4730Hpmfp (including)mfp (including)
Color_laserjet_cm6030Hp**
Color_laserjet_cm6040Hp**
Color_laserjet_cp3505Hp**
Color_laserjet_cp3525Hp**
Color_laserjet_cp4005Hp**
Color_laserjet_cp5525Hp**
Color_laserjet_cp6015Hp**
Color_laserjet_enterprise_cp4520Hp**
Color_laserjet_enterprise_cp4525Hp**
Color_mfp_cm8060Hp- (including)- (including)
Digital_sender_9200cHp**
Digital_sender_9250cHp**
Laserjet_4240Hp**
Laserjet_4250Hp**
Laserjet_4345_mfpHp**
Laserjet_4350Hp**
Laserjet_5200Hp**
Laserjet_9040Hp**
Laserjet_9050Hp**
Laserjet_enterprise_500_colorHpm551 (including)m551 (including)
Laserjet_enterprise_600Hpm601 (including)m601 (including)
Laserjet_enterprise_600Hpm602 (including)m602 (including)
Laserjet_enterprise_600Hpm603 (including)m603 (including)
Laserjet_enterprise_m4555Hpmfp (including)mfp (including)
Laserjet_enterprise_p3015Hp**
Laserjet_m3035Hp**
Laserjet_m5035Hp**
Laserjet_m9040Hp**
Laserjet_m9050Hp**
Laserjet_p3005Hp**
Laserjet_p4014Hp**
Laserjet_p4015Hp**
Laserjet_p4515Hp**

References