HIGH · 10.0

CVE-2011-4161

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 9...

Vulnerability Description

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HpColor Laserjet 3000All versions
HpColor Laserjet 3800All versions
HpColor Laserjet 4700All versions
HpColor Laserjet 4730mfp
HpColor Laserjet 4730 MfpAll versions
HpColor Laserjet 5550All versions
HpColor Laserjet 9500All versions
HpColor Laserjet Cm3530All versions
HpColor Laserjet Cm4540mfp
HpColor Laserjet Cm4730mfp
HpColor Laserjet Cm6030All versions
HpColor Laserjet Cm6040All versions
HpColor Laserjet Cp3505All versions
HpColor Laserjet Cp3525All versions
HpColor Laserjet Cp4005All versions
HpColor Laserjet Cp5525All versions
HpColor Laserjet Cp6015All versions
HpColor Laserjet Enterprise Cp4520All versions
HpColor Laserjet Enterprise Cp4525All versions
HpColor Mfp Cm8060-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4161?

CVE-2011-4161 is a vulnerability with a CVSS score of 10.0 (HIGH). The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 9...

How severe is CVE-2011-4161?

CVE-2011-4161 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4161?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Color Laserjet 3000, Hp Color Laserjet 3800, Hp Color Laserjet 4700, Hp Color Laserjet 4730, Hp Color Laserjet 4730 Mfp.