CVE-2009-0940
Last modified
CVE-2009-0940 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | 8100c Digital Sender | All versions |
| Hp | 9100c Digital Sender | All versions |
| Hp | 9200c Digital Sender | All versions |
| Hp | 9250c Digital Sender | All versions |
| Hp | Color Laserjet | All versions |
| Hp | Color Laserjet 1500 | All versions |
| Hp | Color Laserjet 2500 | All versions |
| Hp | Color Laserjet 2500l | All versions |
| Hp | Color Laserjet 2500lse | All versions |
| Hp | Color Laserjet 2500n | All versions |
| Hp | Color Laserjet 2500tn | All versions |
| Hp | Color Laserjet 2605dtn | All versions |
| Hp | Color Laserjet 4370mfp | 20081211_46.211.2 |
| Hp | Color Laserjet 4600 | All versions |
| Hp | Color Laserjet 4600dn | All versions |
| Hp | Color Laserjet 4600dtn | All versions |
| Hp | Color Laserjet 4600hdn | All versions |
| Hp | Color Laserjet 4650 | All versions |
| Hp | Color Laserjet 4700 | All versions |
| Hp | Color Laserjet 4730 Mfp | All versions |
| Hp | Color Laserjet 5500 | All versions |
| Hp | Color Laserjet 5550 | All versions |
| Hp | Color Laserjet 8500 | All versions |
| Hp | Color Laserjet 8550 | All versions |
| Hp | Color Laserjet 9500 | All versions |
| Hp | Color Laserjet 9500 Mfp | All versions |
| Hp | Color Laserjet 9500mfp | 20070719_05.011.2 |
| Hp | Color Mfp Cm8050 | All versions |
| Hp | Color Mfp Cm8060 | All versions |
| Hp | Digital Senders | All versions |
| Hp | Edgeline Printers | All versions |
| Hp | Laserjet 1000 | All versions |
| Hp | Laserjet 1005 | All versions |
| Hp | Laserjet 1010 | All versions |
| Hp | Laserjet 1012 | All versions |
| Hp | Laserjet 1015 | All versions |
| Hp | Laserjet 1018 | All versions |
| Hp | Laserjet 1018s | All versions |
| Hp | Laserjet 1020 | All versions |
| Hp | Laserjet 1020 Plus | All versions |
| Hp | Laserjet 1022 | All versions |
| Hp | Laserjet 1022n | All versions |
| Hp | Laserjet 1022nw | All versions |
| Hp | Laserjet 1100 | All versions |
| Hp | Laserjet 1150 | All versions |
| Hp | Laserjet 1160 | All versions |
| Hp | Laserjet 1200 | All versions |
| Hp | Laserjet 1300 | All versions |
| Hp | Laserjet 1320 | All versions |
| Hp | Laserjet 2 | All versions |
Showing 50 of 164 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0940?
How severe is CVE-2009-0940?
How do I fix CVE-2009-0940?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0934Cross-site scripting (XSS) vulnerability in ejabberd before …
- CVE-2009-0935The inotify_read function in the Linux kernel 2.6.27 to 2.6.…5.5
- CVE-2009-0936Unspecified vulnerability in Tor before 0.2.0.34 allows atta…
- CVE-2009-0937Unspecified vulnerability in Tor before 0.2.0.34 allows dire…
- CVE-2009-0938Unspecified vulnerability in Tor before 0.2.0.34 allows dire…
- CVE-2009-0939Tor before 0.2.0.34 treats incomplete IPv4 addresses as vali…
- CVE-2009-0941The HP Embedded Web Server (EWS) on HP LaserJet Printers, Ed…
- CVE-2009-0942Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7…
- CVE-2009-0943Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7…
- CVE-2009-0944The Microsoft Office Spotlight Importer in Spotlight in Appl…
- CVE-2009-0945Array index error in the insertItemBefore method in WebKit, …
- CVE-2009-0946Multiple integer overflows in FreeType 2.3.9 and earlier all…
Are you affected by CVE-2009-0940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
