HIGH · 7.6

CVE-2009-0941

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

Vulnerability Description

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Hp8100C Digital Sender-
Hp9100C Digital Sender-
Hp9200C Digital Sender-
Hp9250C Digital Sender-
HpColor LaserjetAll versions
HpColor Laserjet 1500All versions
HpColor Laserjet 2500All versions
HpColor Laserjet 2500LAll versions
HpColor Laserjet 2500LseAll versions
HpColor Laserjet 2500NAll versions
HpColor Laserjet 2500TnAll versions
HpColor Laserjet 2605DtnAll versions
HpColor Laserjet 4370Mfp20081211_46.211.2
HpColor Laserjet 4600All versions
HpColor Laserjet 4600DnAll versions
HpColor Laserjet 4600DtnAll versions
HpColor Laserjet 4600HdnAll versions
HpColor Laserjet 4650All versions
HpColor Laserjet 4700All versions
HpColor Laserjet 4730 MfpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0941?

CVE-2009-0941 is a vulnerability with a CVSS score of 7.6 (HIGH). The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

How severe is CVE-2009-0941?

CVE-2009-0941 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0941?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 8100C Digital Sender, Hp 9100C Digital Sender, Hp 9200C Digital Sender, Hp 9250C Digital Sender, Hp Color Laserjet.