MEDIUM · 5.1

CVE-2009-0940

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intr...

Vulnerability Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

CVSS Score

5.1

MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Hp8100C Digital Sender-
Hp9100C Digital Sender-
Hp9200C Digital Sender-
Hp9250C Digital Sender-
HpColor LaserjetAll versions
HpColor Laserjet 1500All versions
HpColor Laserjet 2500All versions
HpColor Laserjet 2500LAll versions
HpColor Laserjet 2500LseAll versions
HpColor Laserjet 2500NAll versions
HpColor Laserjet 2500TnAll versions
HpColor Laserjet 2605DtnAll versions
HpColor Laserjet 4370Mfp20081211_46.211.2
HpColor Laserjet 4600All versions
HpColor Laserjet 4600DnAll versions
HpColor Laserjet 4600DtnAll versions
HpColor Laserjet 4600HdnAll versions
HpColor Laserjet 4650All versions
HpColor Laserjet 4700All versions
HpColor Laserjet 4730 MfpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0940?

CVE-2009-0940 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intr...

How severe is CVE-2009-0940?

CVE-2009-0940 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0940?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 8100C Digital Sender, Hp 9100C Digital Sender, Hp 9200C Digital Sender, Hp 9250C Digital Sender, Hp Color Laserjet.