CVE-2011-4161: Critical severity hp color laserjet enterprise cp4520 vulnerability
The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4161?
CVE-2011-4161 has a medium severity rating due to potential remote exploitation by attackers.
How do I fix CVE-2011-4161?
To mitigate CVE-2011-4161, users should apply firmware updates provided by HP for the affected printer models.
Which devices are impacted by CVE-2011-4161?
CVE-2011-4161 affects various models of HP Color LaserJet and Digital Sender products.
What are the potential risks associated with CVE-2011-4161?
The risks of CVE-2011-4161 include unauthorized access and potential compromise of sensitive data through open network ports.
Can CVE-2011-4161 be exploited remotely?
Yes, CVE-2011-4161 can be exploited remotely if the affected printer models are accessible over the network.