CVE-2012-5221
Last modified
CVE-2012-5221 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.. EPSS estimates a 3.85% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet 3000 | q7534a |
| Hp | Color Laserjet 3800 | q5981a |
| Hp | Color Laserjet 4700 | q7492a |
| Hp | Color Laserjet 4730 Mfp | cb480a |
| Hp | Color Laserjet 5550 | q3714a |
| Hp | Color Laserjet 9500 Mfp | c8549a |
| Hp | Color Laserjet Cm6030 Mfp | ce664a |
| Hp | Color Laserjet Cm6040 Mfp | q3939a |
| Hp | Color Laserjet Cp3505 | cb442a |
| Hp | Color Laserjet Cp3525 | cc469a |
| Hp | Color Laserjet Cp4005 | cb503a |
| Hp | Color Laserjet Cp6015 | q3932a |
| Hp | Color Laserjet Enterprise Cp4025 | cc490a |
| Hp | Color Laserjet Enterprise Cp4525 | cc493a |
| Hp | Digital Sender 9250c | cb472a |
| Hp | Laserjet 4240 | q7785a |
| Hp | Laserjet 4250 | q5400a |
| Hp | Laserjet 4345 Mfp | q3942a |
| Hp | Laserjet 4350 | q5407a |
| Hp | Laserjet 5200l | q7543a |
| Hp | Laserjet 5200n | q7543a |
| Hp | Laserjet 9040 | q7697a |
| Hp | Laserjet 9040 Mfp | q3721a |
| Hp | Laserjet 9050 | q7697a |
| Hp | Laserjet 9050 Mfp | q3721a |
| Hp | Laserjet Enterprise P3015 | ce526a |
| Hp | Laserjet M3027 Mfp | cb416a |
| Hp | Laserjet M3035 Mfp | cb414a |
| Hp | Laserjet M3035 Mfp | cc519a |
| Hp | Laserjet M4345 Mfp | cb425a |
| Hp | Laserjet M5025 Mfp | q7840a |
| Hp | Laserjet M5035 Mfp | q7829a |
| Hp | Laserjet M9040 Mpf | cc394a |
| Hp | Laserjet M9050 Mpf | cc395a |
| Hp | Laserjet P3005 | q7812a |
| Hp | Laserjet P4014 | cb507a |
| Hp | Laserjet P4015 | cb509a |
| Hp | Laserjet P4515 | cb514a |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-5221?
How severe is CVE-2012-5221?
How do I fix CVE-2012-5221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-5215Unspecified vulnerability on the HP LaserJet Pro M1212nf, M1…
- CVE-2012-5216Cross-site request forgery (CSRF) vulnerability on HP ProCur…
- CVE-2012-5217HP System Management Homepage (SMH) before 7.2.1 allows remo…
- CVE-2012-5218HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.…
- CVE-2012-5219Cross-site scripting (XSS) vulnerability in HP Managed Print…
- CVE-2012-5220Unspecified vulnerability in HP Storage Data Protector 6.20,…
- CVE-2012-5222HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows …
- CVE-2012-5223The proc_deutf function in includes/functions_vbseocp_abstra…
- CVE-2012-5224PHP remote file inclusion vulnerability in vb/includes/vba_c…
- CVE-2012-5225Cross-site scripting (XSS) vulnerability in webscr.php in xC…
- CVE-2012-5226Multiple cross-site scripting (XSS) vulnerabilities in Peel …
- CVE-2012-5227SQL injection vulnerability in administrer/tva.php in Peel S…
Are you affected by CVE-2012-5221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
