CVE-2011-4161
Last modified
CVE-2011-4161 is a vulnerability of currently unknown severity. The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.. EPSS estimates a 13.95% chance of exploitation in the next 30 days.
Description
The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet 3000 | All versions |
| Hp | Color Laserjet 3800 | All versions |
| Hp | Color Laserjet 4700 | All versions |
| Hp | Color Laserjet 4730 | mfp |
| Hp | Color Laserjet 4730 Mfp | All versions |
| Hp | Color Laserjet 5550 | All versions |
| Hp | Color Laserjet 9500 | All versions |
| Hp | Color Laserjet Cm3530 | All versions |
| Hp | Color Laserjet Cm4540 | mfp |
| Hp | Color Laserjet Cm4730 | mfp |
| Hp | Color Laserjet Cm6030 | All versions |
| Hp | Color Laserjet Cm6040 | All versions |
| Hp | Color Laserjet Cp3505 | All versions |
| Hp | Color Laserjet Cp3525 | All versions |
| Hp | Color Laserjet Cp4005 | All versions |
| Hp | Color Laserjet Cp5525 | All versions |
| Hp | Color Laserjet Cp6015 | All versions |
| Hp | Color Laserjet Enterprise Cp4520 | All versions |
| Hp | Color Laserjet Enterprise Cp4525 | All versions |
| Hp | Color Mfp Cm8060 | All versions |
| Hp | Digital Sender 9200c | All versions |
| Hp | Digital Sender 9250c | All versions |
| Hp | Laserjet 4240 | All versions |
| Hp | Laserjet 4250 | All versions |
| Hp | Laserjet 4345 Mfp | All versions |
| Hp | Laserjet 4350 | All versions |
| Hp | Laserjet 5200 | All versions |
| Hp | Laserjet 9040 | All versions |
| Hp | Laserjet 9050 | All versions |
| Hp | Laserjet Enterprise 500 Color | m551 |
| Hp | Laserjet Enterprise 600 | m601 |
| Hp | Laserjet Enterprise 600 | m602 |
| Hp | Laserjet Enterprise 600 | m603 |
| Hp | Laserjet Enterprise M4555 | mfp |
| Hp | Laserjet Enterprise P3015 | All versions |
| Hp | Laserjet M3035 | All versions |
| Hp | Laserjet M5035 | All versions |
| Hp | Laserjet M9040 | All versions |
| Hp | Laserjet M9050 | All versions |
| Hp | Laserjet P3005 | All versions |
| Hp | Laserjet P4014 | All versions |
| Hp | Laserjet P4015 | All versions |
| Hp | Laserjet P4515 | All versions |
References
- http://www.kb.cert.org/vuls/id/717921US Government Resource
- http://www.kb.cert.org/vuls/id/717921US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4161?
How severe is CVE-2011-4161?
How do I fix CVE-2011-4161?
Are you affected by CVE-2011-4161?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
