Vulnerability Description
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Color Laserjet | 4650 |
| Hp | Color Laserjet 4600 | All versions |
| Hp | Laserjet 2500 | All versions |
| Hp | Laserjet 3000 | All versions |
| Hp | Laserjet 3700 | All versions |
| Hp | Laserjet 4100 Mfp | All versions |
| Hp | Laserjet 4200 | All versions |
| Hp | Laserjet 4300 | All versions |
| Hp | Laserjet 9000 | All versions |
| Hp | Laserjet 9000 Mfp | All versions |
| Hp | Laserjet 9040 Mpf | All versions |
| Hp | Laserjet 9050 | All versions |
| Hp | Laserjet 9050 Mpf | All versions |
| Hp | Laserjet 9055 | All versions |
| Hp | Laserjet 9065 | All versions |
| Hp | Laserjet 9500 | All versions |
| Hp | Laserjet 9500 Mpf | All versions |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBPVendor Advisory
- http://securitytracker.com/id?1011671Vendor Advisory
- http://www.securityfocus.com/bid/11297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17634
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBPVendor Advisory
- http://securitytracker.com/id?1011671Vendor Advisory
- http://www.securityfocus.com/bid/11297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17634
FAQ
What is CVE-2004-2439?
CVE-2004-2439 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
How severe is CVE-2004-2439?
CVE-2004-2439 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2439?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Color Laserjet, Hp Color Laserjet 4600, Hp Laserjet 2500, Hp Laserjet 3000, Hp Laserjet 3700.