CVE-2009-0940
Last modified
CVE-2009-0940 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | 8100c Digital Sender | All versions |
| Hp | 9100c Digital Sender | All versions |
| Hp | 9200c Digital Sender | All versions |
| Hp | 9250c Digital Sender | All versions |
| Hp | Color Laserjet | All versions |
| Hp | Color Laserjet 1500 | All versions |
| Hp | Color Laserjet 2500 | All versions |
| Hp | Color Laserjet 2500l | All versions |
| Hp | Color Laserjet 2500lse | All versions |
| Hp | Color Laserjet 2500n | All versions |
| Hp | Color Laserjet 2500tn | All versions |
| Hp | Color Laserjet 2605dtn | All versions |
| Hp | Color Laserjet 4370mfp | 20081211_46.211.2 |
| Hp | Color Laserjet 4600 | All versions |
| Hp | Color Laserjet 4600dn | All versions |
| Hp | Color Laserjet 4600dtn | All versions |
| Hp | Color Laserjet 4600hdn | All versions |
| Hp | Color Laserjet 4650 | All versions |
| Hp | Color Laserjet 4700 | All versions |
| Hp | Color Laserjet 4730 Mfp | All versions |
| Hp | Color Laserjet 5500 | All versions |
| Hp | Color Laserjet 5550 | All versions |
| Hp | Color Laserjet 8500 | All versions |
| Hp | Color Laserjet 8550 | All versions |
| Hp | Color Laserjet 9500 | All versions |
| Hp | Color Laserjet 9500 Mfp | All versions |
| Hp | Color Laserjet 9500mfp | 20070719_05.011.2 |
| Hp | Color Mfp Cm8050 | All versions |
| Hp | Color Mfp Cm8060 | All versions |
| Hp | Digital Senders | All versions |
| Hp | Edgeline Printers | All versions |
| Hp | Laserjet 1000 | All versions |
| Hp | Laserjet 1005 | All versions |
| Hp | Laserjet 1010 | All versions |
| Hp | Laserjet 1012 | All versions |
| Hp | Laserjet 1015 | All versions |
| Hp | Laserjet 1018 | All versions |
| Hp | Laserjet 1018s | All versions |
| Hp | Laserjet 1020 | All versions |
| Hp | Laserjet 1020 Plus | All versions |
| Hp | Laserjet 1022 | All versions |
| Hp | Laserjet 1022n | All versions |
| Hp | Laserjet 1022nw | All versions |
| Hp | Laserjet 1100 | All versions |
| Hp | Laserjet 1150 | All versions |
| Hp | Laserjet 1160 | All versions |
| Hp | Laserjet 1200 | All versions |
| Hp | Laserjet 1300 | All versions |
| Hp | Laserjet 1320 | All versions |
| Hp | Laserjet 2 | All versions |
Showing 50 of 164 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0940?
How severe is CVE-2009-0940?
How do I fix CVE-2009-0940?
Are you affected by CVE-2009-0940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
