CVE-2009-0940: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/configresultYesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/setconfigpassword.html/config.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block HTTP(S) requests to the specific Embedded Web Server endpoints /hp/device/config_result_YesNo.html/config and /hp/device/set_config_password.html/config at the network edge (firewall, WAF, or proxy) to prevent CSRF exploitation of the HP Embedded Web Server (EWS) on the listed HP printers, Edgeline printers, and Digital Senders.
- Compensating control
Restrict access to the HP Embedded Web Server (EWS) on the affected devices to trusted management IP addresses or a management VLAN using firewall/ACL rules so only authorized hosts can reach the printer web interface.
- Operational
For each affected device from the list, verify the administrator password and network configuration (including IP changes). If passwords or network settings appear altered or potentially compromised, reset the administrator password to a secure value and restore the correct network configuration via the device local interface or console.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0940?
CVE-2009-0940 is rated as a medium severity vulnerability due to its potential for CSRF attacks that could hijack users' intranet connectivity.
How do I fix CVE-2009-0940?
To fix CVE-2009-0940, ensure that the firmware of affected HP printers is updated to the latest version provided by HP.
Which devices are affected by CVE-2009-0940?
CVE-2009-0940 affects a wide range of HP LaserJet printers, Edgeline printers, and Digital Senders.
What type of attack does CVE-2009-0940 allow?
CVE-2009-0940 allows attackers to perform cross-site request forgery (CSRF), potentially enabling them to make unauthorized requests on behalf of users.
Can CVE-2009-0940 be exploited remotely?
Yes, CVE-2009-0940 can be exploited remotely, allowing attackers to hijack user sessions without physical access to the vulnerable printers.