CVE-2012-5221: Medium severity hp color laserjet 3000 vulnerability
Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3xxx, 47xx, 5550, 9500, CM60xx, CP35xx, CP4005, and CP6015; Color LaserJet Enterprise CP4xxx; and 9250c Digital Sender with model-dependent firmware through 52.x allows remote attackers to read arbitrary files via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5221?
CVE-2012-5221 has a medium severity rating as it allows unauthorized local file access through directory traversal.
How do I fix CVE-2012-5221?
To mitigate CVE-2012-5221, update the affected HP printer firmware to the latest version provided by HP.
Which HP printer models are affected by CVE-2012-5221?
CVE-2012-5221 affects several HP LaserJet and Color LaserJet models, including the LaserJet 4xxx, 5200, CP4005, and more.
What kind of attack is possible with CVE-2012-5221?
An attacker could exploit CVE-2012-5221 to execute commands or access sensitive files on the printer or connected systems via crafted PostScript files.
Is there a workaround available for CVE-2012-5221?
A potential workaround for CVE-2012-5221 involves restricting printer access to trusted users through network configurations.