Unknown
CVE-2011-4161
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- color laserjet 3000,
- color laserjet 3800,
- color laserjet 4700,
- color laserjet 4730 mfp,
- color laserjet 4730 mfp,
- color laserjet 5550,
- color laserjet 9500,
- color laserjet cm3530,
- color laserjet cm4540 mfp,
- color laserjet cm4730 mfp,
- color laserjet cm6030,
- color laserjet cm6040,
- color laserjet cp3505,
- color laserjet cp3525,
- color laserjet cp4005,
- color laserjet cp5525,
- color laserjet cp6015,
- color laserjet enterprise cp4520,
- color laserjet enterprise cp4525,
- color mfp cm8060 -,
- digital sender 9200c,
- digital sender 9250c,
- laserjet 4240,
- laserjet 4250,
- laserjet 4345 mfp,
- laserjet 4350,
- laserjet 5200,
- laserjet 9040,
- laserjet 9050,
- laserjet enterprise 500 color m551,
- laserjet enterprise 600 m601,
- laserjet enterprise 600 m602,
- laserjet enterprise 600 m603,
- laserjet enterprise m4555 mfp,
- laserjet enterprise p3015,
- laserjet m3035,
- laserjet m5035,
- laserjet m9040,
- laserjet m9050,
- laserjet p3005,
- laserjet p4014,
- laserjet p4015,
- laserjet p4515
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: