CVE-2011-4161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/12/2011
Last modified:
11/04/2025

Description

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 color M551, 600, M4555 MFP, and P3015 enables the Remote Firmware Update (RFU) setting, which allows remote attackers to execute arbitrary code by using a session on TCP port 9100 to upload a crafted firmware update.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:hp:color_laserjet_3000:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_3800:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_4700:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_4730:mfp:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_4730_mfp:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_5550:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_9500:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cm3530:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cm4540:mfp:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cm4730:mfp:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cm6030:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cm6040:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cp3505:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cp3525:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:color_laserjet_cp4005:*:*:*:*:*:*:*:*