VulnerabilityModified
CVE-2004-2439
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
MEDIUM 5.0EPSS 2.22%
Does this matter?
Lower severity and a low EPSS score (2.22%). Track it; it rarely justifies an emergency change on its own.
Description
The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.22% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- hp/color laserjet · hp/color laserjet 4600 · hp/laserjet 2500 · hp/laserjet 3000 · hp/laserjet 3700 · hp/laserjet 4100 mfp · hp/laserjet 4200 · hp/laserjet 4300 · hp/laserjet 9000 · hp/laserjet 9000 mfp · hp/laserjet 9040 mpf · hp/laserjet 9050 · hp/laserjet 9050 mpf · hp/laserjet 9055 · hp/laserjet 9065 · hp/laserjet 9500 · hp/laserjet 9500 mpf
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBPI01085Vendor Advisory
- http://securitytracker.com/id?1011671Vendor Advisory
- http://www.securityfocus.com/bid/11297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17634
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=PSD_HPSBPI01085Vendor Advisory
- http://securitytracker.com/id?1011671Vendor Advisory
- http://www.securityfocus.com/bid/11297
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17634
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.