First published: Thu Apr 06 2006(Updated: )
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Color LaserJet 2500 | ||
HP Color LaserJet | =4600hdn | |
HP color LaserJet 2500lse | ||
HP Color LaserJet 2500n | ||
HP Color LaserJet 2500n | ||
HP Color LaserJet 2500 Toolbox | ||
HP Color LaserJet | =4600dtn | |
HP Color LaserJet 4600 Toolbox | ||
HP Color LaserJet 4600dtn | ||
HP Color LaserJet 2500n | ||
HP Color LaserJet | =4600dn |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1654 has a moderate severity rating due to its potential to allow unauthorized access to sensitive files.
To fix CVE-2006-1654, update the HP Color LaserJet Toolbox software to a version released after April 2, 2006.
CVE-2006-1654 affects HP Color LaserJet 2500 and 4600 series printers running specific versions of their Toolbox software.
Yes, CVE-2006-1654 allows remote attackers to exploit the directory traversal vulnerability to read arbitrary files.
If your system is vulnerable to CVE-2006-1654, it is essential to immediately update the software or disable remote access features until an update is applied.