CVE-2011-4161

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
hpCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
hpcolor_laserjet_3000
*
hpcolor_laserjet_3800
*
hpcolor_laserjet_4700
*
hpcolor_laserjet_4730_mfp
*
hpcolor_laserjet_5550
*
hpcolor_laserjet_9500
*
hpcolor_laserjet_cm3530
*
hpcolor_laserjet_cm6030
*
hpcolor_laserjet_cm6040
*
hpcolor_laserjet_cp3505
*
hpcolor_laserjet_cp3525
*
hpcolor_laserjet_cp4005
*
hpcolor_laserjet_cp5525
*
hpcolor_laserjet_cp6015
*
hpcolor_laserjet_enterprise_cp4520
*
hpcolor_laserjet_enterprise_cp4525
*
hpcolor_mfp_cm8060
-
hpdigital_sender_9200c
*
hpdigital_sender_9250c
*
hplaserjet_4240
*
hplaserjet_4250
*
hplaserjet_4345_mfp
*
hplaserjet_4350
*
hplaserjet_5200
*
hplaserjet_9040
*
hplaserjet_9050
*
hplaserjet_enterprise_p3015
*
hplaserjet_m3035
*
hplaserjet_m5035
*
hplaserjet_m9040
*
hplaserjet_m9050
*
hplaserjet_p3005
*
hplaserjet_p4014
*
hplaserjet_p4015
*
hplaserjet_p4515
*
𝑥
= Vulnerable software versions
Common Weakness Enumeration