CVE-2006-1654

UnknownEPSS 4.68%

Last modified

CVE-2006-1654 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.. EPSS estimates a 4.68% chance of exploitation in the next 30 days.

Description

Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.

Metrics

EPSS Probability
4.68%

90.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HpColor Laserjet 2500 ToolboxAll versions
HpColor Laserjet 4600 ToolboxAll versions
HpColor Laserjet4600dn
HpColor Laserjet4600dtn
HpColor Laserjet4600hdn
HpColor Laserjet 2500All versions
HpColor Laserjet 2500lAll versions
HpColor Laserjet 2500lseAll versions
HpColor Laserjet 2500nAll versions
HpColor Laserjet 2500tnAll versions
HpColor Laserjet 4600All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-1654?
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
How severe is CVE-2006-1654?
Severity scoring for CVE-2006-1654 is pending analysis. The EPSS model estimates a 4.68% probability of exploitation in the next 30 days.
How do I fix CVE-2006-1654?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-1654?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST